CVE-2019-13237
MEDIUMAlkacon OpenCms 10.5.4-10.5.5 - Local File Inclusion via Multiple Admin Endpoints
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-13237. PoCs published by Aetsu.
AI-analyzed exploit summary The exploit demonstrates multiple Local File Inclusion (LFI) vulnerabilities in Alkacon OpenCMS 10.5.x via the 'closelink' parameter in various admin endpoints. The PoC includes HTTP POST requests with path traversal sequences to access sensitive files like 'web.xml' and 'opencms.log'.
Description
In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and /system/workplace/admin/history/settings/index.jsp.
Exploits (1)
The exploit demonstrates multiple Local File Inclusion (LFI) vulnerabilities in Alkacon OpenCMS 10.5.x via the 'closelink' parameter in various admin endpoints. The PoC includes HTTP POST requests with path traversal sequences to access sensitive files like 'web.xml' and 'opencms.log'.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N