QID 150760
Date Published: 2023-12-14
QID 150760: OpenCMS Cross-Site Scripting (XSS) Vulnerability (CVE-2023-6379)
OpenCms from Alkacon Software is a professional, easy to use website content management system (CMS) based on Java and XML technology.
A Cross-Site Scripting (XSS) vulnerability exists in Mercury template of OpenCMS.
Affected versions:
OpenCMS version 14
OpenCMS version 15
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request to "overview/" endpoint with vulnerable parameter containing Cross-Site Scripting (XSS) payload and based on the response confirms the vulnerability on the target application.
Successful exploitation could allow an attacker to execute arbitrary JavaScript code in the context of the interface or allow the attacker to access sensitive, browser-based information.
Solution
Customers are advised to upgrade to OpenCMS 16 to remediate this vulnerability.
Vendor References
CVEs related to QID 150760
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| OpenCMS Downloads |
|