Description
A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.
Published: 2026-05-08
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a reflected XSS vulnerability that occurs when user input is unsanitized within the cmis-online/type endpoint of Alkacon OpenCms. By crafting a request containing malicious characters, an attacker can cause the browser of any user who visits the affected URL to execute arbitrary JavaScript, potentially hijacking sessions, defacing content, or injecting malware.

Affected Systems

Alkacon OpenCms installations running any version older than 10.5.1 are impacted, specifically through the cmis-online/type module used for CMIS operations.

Risk and Exploitability

EPSS data is not available and the issue is not listed in CISA KEV, indicating no publicly known exploit as of now. The CVSS score is also unspecified, so the precise severity cannot be quantified. However, the vulnerability can be triggered remotely without requiring special privileges or authentication, making it a serious concern for any exposed site.

Generated by OpenCVE AI on May 8, 2026 at 06:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Alkacon OpenCms to version 10.5.1 or newer.
  • If an upgrade is not immediately possible, limit external access to the CMIS endpoint or apply a Web‑Application Firewall to block suspicious requests.
  • Validate and escape all user input processed by the cmis‑online/type endpoint to prevent script injection.

Generated by OpenCVE AI on May 8, 2026 at 06:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 08 May 2026 06:45:00 +0000

Type Values Removed Values Added
Title Cross‑site scripting via the cmis-online/type endpoint in Alkacon OpenCms before 10.5.1
First Time appeared Alkacon
Alkacon opencms
Weaknesses CWE-79
Vendors & Products Alkacon
Alkacon opencms

Fri, 08 May 2026 05:00:00 +0000

Type Values Removed Values Added
Description A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-08T13:46:46.335Z

Reserved: 2023-09-08T00:00:00.000Z

Link: CVE-2023-42343

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-08T05:16:09.420

Modified: 2026-05-08T05:16:09.420

Link: CVE-2023-42343

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-08T06:30:46Z

Weaknesses