Record summary

CVE-2023-6379 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing session.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List14affected
15affected
GitHub Advisory14.0.0 to < 16.0.0 · Fixed in 16.0.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMOpenCMS 14 & 15 - Cross Site ScriptingCVSS 6.1

Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template.

Impact

Unauthenticated attackers can inject malicious JavaScript through multiple parameters in OpenCMS Mercury template pages to steal user session cookies and execute attacks against OpenCMS users.

Remediation

Update to version OpenCMS 16

WeaknessesCWE-79
Authorsmsegoviag
Template tagscve2023cveopencmsxssalkaconvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:alkacon:opencms:*:*:*:*:*:*:*:*
Shodan: title:"opencms"
Shodan: http.title:"opencms"
Shodan: cpe:"cpe:2.3:a:alkacon:opencms"
Shodan: /opencms/
FOFA: title="opencms"
Google: intitle:"opencms"

Source: ProjectDiscovery

References

4