Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
An issue in OpenCRX v.5.2.2 allows a remote attacker to execute arbitrary code via a crafted request.
An issue in OpenCRX v.5.2.2 allows a remote attacker to execute arbitrary code via a crafted request.
OpenCRX before v5.2.2 was discovered to be vulnerable to password enumeration due to the difference in error messages received during a password reset which could enable an attacker to determine if a username, email or ID is valid.
In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password reset functionality. This allows execution of external javascript files on any user of the openCRX instance.