Description
Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing session.
No analysis available yet.
Remediation
Vendor Solution
The vulnerabilities have been fixed in OpenCms version 16.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-w62v-q77r-66cc | Alkacon OpenCMS XSS via Mercury template |
References
History
Tue, 01 Oct 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-10-01T14:47:25.647Z
Reserved: 2023-11-29T10:30:51.994Z
Link: CVE-2023-6379
Updated: 2024-08-02T08:28:21.815Z
Status : Modified
Published: 2023-12-13T11:15:07.100
Modified: 2024-11-21T08:43:44.673
Link: CVE-2023-6379
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA