vendor:
OpenCms
by:
Sureshbabu Narvaneni
4.6
CVSS
MEDIUM
Stored Cross Site Scripting
79
CWE
Product Name: OpenCms
Affected Version From: 10.5.3
Affected Version To: 10.5.3
Patch Exists: YES
Related CWE: CVE-2018-8815
CPE: a:alkacon:opencms
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 14.04 x86_64/Kali Linux 4.12 i686
2018
OpenCMS 10.5.3 Stored Cross Site Scripting Vulnerability
Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to inject arbitrary web script or HTML via a malicious SVG image.
Mitigation:
Upgrade to latest release.