QID 150761
Date Published: 2023-12-14
QID 150761: OpenCMS Open Redirect Vulnerability (CVE-2023-6380)
OpenCms from Alkacon Software is a professional, easy to use website content management system (CMS) based on Java and XML technology.
A Open Redirect vulnerability exists in Mercury template of OpenCMS due to improper sanitization of the 'URI' parameter.
Affected versions:
OpenCMS version 14
OpenCMS version 15
QID Detection Logic (Unauthenticated):
This QID initially sends a HTTP GET request to the "system/modules/alkacon.mercury.template.jsondemo/elements/jsonapi.jsp" endpoint to verify its accessibility. It then sumbits the vulnerable parameter 'URI' containing arbitrary payload and based 'Location' response header value confirms the vulnerability on the target application.
Successful exploitation of this vulnerability could allow an attacker to trick a user into visiting a specially crafted link which could redirect them to a malicious site and compromise them.
CVEs related to QID 150761
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| OpenCMS Downloads |
|