QID 150773

Date Published: 2023-12-06

QID 150773: OpenCMS Unauthenticated XXE Vulnerability (CVE-2023-42344)

OpenCms from Alkacon Software, the open source content management system (CMS) based on Java and XML for public internet website, extranet or intranet.

On affected versions of OpenCms, a XML external entity injection (XXE) vulnerability exists.

Affected Versions:
OpenCMS version from 9.0.0 to 10.5.0

QID Detection Logic (unauthenticated):
This QID sends an HTTP POST request with a XXE payload to access the server file /etc/passwd and, based on the response, confirms if the target is vulnerable.

Successful exploitation of the vulnerability may allow a remote attacker to execute arbitrary code or read sensitive files on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade to OpenCMS 10.5.1 or later to patch the vulnerability. For more information regarding the vulnerability, please refer to the CVE-2023-42344 .

    Vendor References

    CVEs related to QID 150773

    Software Advisories
    Advisory ID Software Component Link
    OpenCMS URL Logo www.opencms.org/en/modules/downloads/dl-opencms-16.0.0-source.html