CVE-2023-6379

MEDIUM NUCLEI

Alkacon Software Open CMS - Mercury Template <15 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing session.

Nuclei Templates (1)

OpenCMS 14 & 15 - Cross Site Scripting
MEDIUMVERIFIEDby msegoviag
Shodan: title:"opencms" || http.title:"opencms" || cpe:"cpe:2.3:a:alkacon:opencms" || /opencms/
FOFA: title="opencms"

Scores

CVSS v3 5.4
EPSS 0.1862
EPSS Percentile 95.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
alkacon/opencms 14.0.0 - 16.0.0
org.opencms/opencms-core 14.0.0 - 16.0.0Maven
Published Dec 13, 2023
Tracked Since Feb 18, 2026