CVE-2023-6379
Cross-site Scripting in Alkacon Software OpenCms
Record summary
CVE-2023-6379 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.
Description
Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing session.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Open CMSBrowse Alkacon / Open CMSDefault status: unaffected | CVE List | 14 | affected |
| 15 | affected | ||
org.opencms:opencms-coreBrowse Maven / org.opencms:opencms-core | GitHub Advisory | 14.0.0 to < 16.0.0 · Fixed in 16.0.0 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMOpenCMS 14 & 15 - Cross Site ScriptingCVSS 6.1
Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template.
Impact
Unauthenticated attackers can inject malicious JavaScript through multiple parameters in OpenCMS Mercury template pages to steal user session cookies and execute attacks against OpenCMS users.
Remediation
Update to version OpenCMS 16
Source: ProjectDiscovery