VYPR
Moderate severityNVD Advisory· Published Jun 21, 2023· Updated Dec 6, 2024

CVE-2023-33725

CVE-2023-33725

Description

Broadleaf 5.x and 6.x (including 5.2.25-GA and 6.2.6-GA) was discovered to contain a cross-site scripting (XSS) vulnerability via a customer signup with a crafted email address. This is fixed in 6.2.6.1-GA.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.broadleafcommerce:broadleafMaven
>= 5.0.0-GA, < 6.2.7-GA6.2.7-GA

Affected products

2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.