First published: Sat Nov 18 2023(Updated: )
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Name Field.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.opencrx:opencrx-core-models | <=5.2.0 | |
Opencrx Opencrx | =5.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40814 is a vulnerability in OpenCRX version 5.2.0 that allows for HTML injection via the Accounts Name Field.
The severity of CVE-2023-40814 is dependent on the impact of the injected HTML code, but it can potentially lead to unauthorized access or data manipulation.
You can determine if you are using an affected version of OpenCRX by checking if you have version 5.2.0 installed.
To fix the CVE-2023-40814 vulnerability, you should upgrade to a version of OpenCRX that is not affected by this vulnerability.
You can find more information about CVE-2023-40814 on the following websites: [esecforte.com](https://www.esecforte.com/cve-2023-40814-html-injection-accounts/), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-40814), [GitHub](https://github.com/advisories/GHSA-chj5-8wxj-rxg8).