Description
A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp.
Published: 2026-05-08
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the updateModelGroups.jsp page of Alkacon OpenCms allows an attacker to inject arbitrary client‑side script code into pages rendered to other users. This vulnerability can lead to session hijacking, credential theft, or the execution of malicious actions within a victim’s browser context. The weakness lies in insufficient filtering of user‑controlled input before it is displayed, a classic Cross‑Site Scripting problem.

Affected Systems

Alkacon OpenCms versions released prior to 16 are affected. No specific patch version is listed in the advisory, so any deployment of OpenCms before the 16 release should be treated as vulnerable.

Risk and Exploitability

The severity has not been quantified in the CVE entry, and no EPSS value is available, but the issue is a client-side vulnerability that can be triggered via a web request to the vulnerable page. Because the payload is delivered to browsers, the vector is likely network‑based and can be abused by anyone able to send HTTP requests to the web application. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not been widely exploited publicly at the time of this analysis.

Generated by OpenCVE AI on May 8, 2026 at 06:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Alkacon OpenCms to version 16 or later to eliminate the vulnerable file
  • If an upgrade is not immediately possible, restrict or disable access to updateModelGroups.jsp, limiting it to privileged administrators only
  • Apply server‑side input validation to strip or encode script tags and other executable markup before rendering content
  • Monitor application logs for attempts to access updateModelGroups.jsp or to inject malicious scripts

Generated by OpenCVE AI on May 8, 2026 at 06:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 08 May 2026 06:45:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting via updateModelGroups.jsp in Alkacon OpenCms
First Time appeared Alkacon
Alkacon opencms
Weaknesses CWE-79
Vendors & Products Alkacon
Alkacon opencms

Fri, 08 May 2026 05:00:00 +0000

Type Values Removed Values Added
Description A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-08T12:59:37.304Z

Reserved: 2023-09-08T00:00:00.000Z

Link: CVE-2023-42345

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-08T05:16:09.703

Modified: 2026-05-08T05:16:09.703

Link: CVE-2023-42345

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-08T06:30:46Z

Weaknesses