Impact
The flaw is a reflected XSS vulnerability that occurs when user input is unsanitized within the cmis-online/type endpoint of Alkacon OpenCms. By crafting a request containing malicious characters, an attacker can cause the browser of any user who visits the affected URL to execute arbitrary JavaScript, potentially hijacking sessions, defacing content, or injecting malware.
Affected Systems
Alkacon OpenCms installations running any version older than 10.5.1 are impacted, specifically through the cmis-online/type module used for CMIS operations.
Risk and Exploitability
EPSS data is not available and the issue is not listed in CISA KEV, indicating no publicly known exploit as of now. The CVSS score is also unspecified, so the precise severity cannot be quantified. However, the vulnerability can be triggered remotely without requiring special privileges or authentication, making it a serious concern for any exposed site.
OpenCVE Enrichment