Medium severity6.1NVD Advisory· Published Jun 21, 2023· Updated Jun 17, 2026
CVE-2023-33725
CVE-2023-33725
Description
Broadleaf 5.x and 6.x (including 5.2.25-GA and 6.2.6-GA) was discovered to contain a cross-site scripting (XSS) vulnerability via a customer signup with a crafted email address. This is fixed in 6.2.6.1-GA.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.broadleafcommerce:broadleafMaven | >= 5.0.0-GA, < 6.2.7-GA | 6.2.7-GA |
Affected products
3- cpe:2.3:a:broadleafcommerce:broadleaf_commerce:*:*:*:*:*:*:*:*Range: >=5.0,<=5.2.25-ga
- Broadleaf/Broadleafdescription
Patches
Vulnerability mechanics
References
3- github.com/Contrast-Security-OSS/Burptrast/tree/main/docs/CVE-2023-33725nvdExploitMitigationThird Party AdvisoryWEB
- github.com/advisories/GHSA-3862-fmr3-4f3hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-33725ghsaADVISORY
News mentions
0No linked articles in our index yet.