Vulnerabilities > Opencrx > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-09-29 | CVE-2021-25959 | Cross-site Scripting vulnerability in Opencrx In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. | 4.3 |
2020-11-24 | CVE-2020-7378 | Improper Authentication vulnerability in Opencrx CRIXP OpenCRX version 4.30 and 5.0-20200717 and prior suffers from an unverified password change vulnerability. | 6.4 |