Showing 2 vulnerabilities on this page for Open CMS

Signals CISA KEV Ransomware Nuclei
Alkacon vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Open Redirect in Alkacon Software OpenCms

Open redirect vulnerability has been found in the Open CMS product affecting versions 14 and 15 of the 'Mercury' template. An attacker could create a specially crafted URL and send it to a specific user to redirect them to a malicious site and compromise them. Exploitation of this vulnerability is possible due to the fact that there is no proper sanitization of the 'URI' parameter.

CWE-601Dec 13, 20231 related artifact
CVSS6.1v3.1EPSS1.59%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Cross-site Scripting in Alkacon Software OpenCms

Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing session.

CWE-79Dec 13, 20231 related artifact
CVSS5.4v3.1EPSS1.75%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX