QID 150773
Date Published: 2023-12-06
QID 150773: OpenCMS Unauthenticated XXE Vulnerability (CVE-2023-42344)
OpenCms from Alkacon Software, the open source content management system (CMS) based on Java and XML for public internet website, extranet or intranet.
On affected versions of OpenCms, a XML external entity injection (XXE) vulnerability exists.
Affected Versions:
OpenCMS version from 9.0.0 to 10.5.0
QID Detection Logic (unauthenticated):
This QID sends an HTTP POST request with a XXE payload to access the server file /etc/passwd and, based on the response, confirms if the target is vulnerable.
Successful exploitation of the vulnerability may allow a remote attacker to execute arbitrary code or read sensitive files on the target system.
Solution
Customers are advised to upgrade to OpenCMS 10.5.1 or later to patch the vulnerability. For more information regarding the vulnerability, please refer to the CVE-2023-42344 .
Vendor References
CVEs related to QID 150773
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| OpenCMS |
|