CVE-2023-6379
MEDIUM NUCLEIAlkacon Software Open CMS - Mercury Template <15 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing session.
Nuclei Templates (1)
OpenCMS 14 & 15 - Cross Site Scripting
MEDIUMVERIFIEDby msegoviag
Shodan:
title:"opencms" || http.title:"opencms" || cpe:"cpe:2.3:a:alkacon:opencms" || /opencms/
FOFA:
title="opencms"
Scores
CVSS v3
5.4
EPSS
0.1862
EPSS Percentile
95.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
alkacon/opencms
14.0.0 - 16.0.0
org.opencms/opencms-core
14.0.0 - 16.0.0Maven
Published
Dec 13, 2023
Tracked Since
Feb 18, 2026