Moderate severityNVD Advisory· Published Jun 21, 2023· Updated Dec 6, 2024
CVE-2023-33725
CVE-2023-33725
Description
Broadleaf 5.x and 6.x (including 5.2.25-GA and 6.2.6-GA) was discovered to contain a cross-site scripting (XSS) vulnerability via a customer signup with a crafted email address. This is fixed in 6.2.6.1-GA.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.broadleafcommerce:broadleafMaven | >= 5.0.0-GA, < 6.2.7-GA | 6.2.7-GA |
Affected products
2- Broadleaf/Broadleafdescription
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.