CVE-2023-40817
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Nov 18, 2023
Updated: Nov 22, 2023
CWE ID 79
Summary
CVE-2023-40817 is a vulnerability affecting OpenCRX version 5.2.0. An attacker can exploit this issue by injecting malicious HTML code into the Product Configuration Name Field. Successful exploitation could lead to unintended execution of malicious scripts within the web application, potentially compromising sensitive data or granting unauthorized access to the affected system. Users are advised to update to a patched version of OpenCRX as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share