github.com
https://github.com/alkacon/opencms-core CVE-2023-42343
MEDIUMNuclei
Alkacon OpenCms is vulnerable to XSS via cmis-online/type
Record summary
CVE-2023-42343 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 8, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
org.opencms:opencms-coreBrowse Maven / org.opencms:opencms-core | GitHub Advisory | Before 16.0 · Fixed in 16.0 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMOpenCMS - Cross-Site Scripting
OpenCMS below 10.5.1 is vulnerable to Cross-Site Scripting vulnerability.
Impact
Unauthenticated attackers can inject malicious JavaScript through the id parameter in CMIS endpoints to steal user session cookies and execute attacks against OpenCMS users.
Remediation
Fixed in 10.5.1.
AuthorsDhiyaneshDK
Template tagscvecve2023xssopencmsvuln
Shodan: /opencms/
Shodan: http.title:"opencms"
Shodan: cpe:"cpe:2.3:a:alkacon:opencms"
FOFA: title="opencms"
Google: intitle:"opencms"
Source: ProjectDiscovery
References
3labs.watchtowr.com
https://labs.watchtowr.com/xxe-you-can-depend-on-me-opencms nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-42343