vendor:
OpenCMS
by:
Aetsu
6.1
CVSS
MEDIUM
Multiple XSS
79
CWE
Product Name: OpenCMS
Affected Version From: 10.5.4
Affected Version To: 10.5.5
Patch Exists: YES
Related CWE: CVE-2019-13236
CPE: a:alkacon:opencms:10.5.5
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: 10.5.5 / 10.5.4
2019
Alkacon OpenCMS 10.5.x – Multiple XSS in Alkacon OpenCms Site Management
Multiple XSS vulnerabilities were discovered in Alkacon OpenCMS 10.5.x. In Site Management, a stored XSS was found in the 'Affected resource title.0' field. In Treeview, a reflected XSS was found in the 'Affected resource type' field. In Workspace tools, a stored XSS was found in the 'Affected resource message.0' field. In Index sources, a stored XSS was found in the 'Affected resource name.0' field. In Index sources, a stored XSS was found in the 'Affected resource name.0' field of the 'New field configuration' page.
Mitigation:
Users should upgrade to the latest version of Alkacon OpenCMS 10.5.x. Additionally, users should ensure that input is properly sanitized and validated.