VYPR

Maven package

org.opencrx/opencrx-gradle

pkg:maven/org.opencrx/opencrx-gradle

Vulnerabilities (1)

  • CVE-2021-25959Sep 29, 2021
    affected >= 4.0.0, < 5.2.0fixed 5.2.0

    In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. This allows execution of external javascript files on any user of the openCRX instance.