Two Cross-Site Scripting vulnerabilities have been discovered in Alkacon's OpenCMS affecting version 16, which could allow a user having the roles of gallery editor or VFS resource manager will have the permission to upload images in the .svg format containing JavaScript code. The code will be executed the moment another user accesses the image.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2024-05-30T11:11:30.216Z

Updated: 2024-08-01T21:18:06.333Z

Reserved: 2024-05-30T07:36:50.487Z

Link: CVE-2024-5521

cve-icon Vulnrichment

Updated: 2024-08-01T21:18:06.333Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-30T12:15:11.090

Modified: 2024-05-30T13:15:41.297

Link: CVE-2024-5521

cve-icon Redhat

No data.