First published: Sat Nov 18 2023(Updated: )
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Product Configuration Name Field.
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.opencrx:opencrx-core-models | <=5.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is GHSA-96q4-7fwr-gmxh.
The title of the vulnerability is 'OpenCRX version 5.2.0 is vulnerable to HTML injection via the Product Configuration Name Field'.
The OpenCRX version 5.2.0 is vulnerable to HTML injection via the Product Configuration Name Field.
OpenCRX version 5.2.0 is affected.
The vulnerability is classified under CWE-79.
The NIST CVE ID is CVE-2023-40817.
You can find more information about this vulnerability at the following references: [link1], [link2], [link3].