QID 730984
Date Published: 2023-11-27
QID 730984: OpenCMS Unauthenticated Extensible Markup Language (XML) External Entity (XXE) Vulnerability
OpenCMS is vulnerable to unauthenticated XXE vulnerability. The vulnerability may allow an unauthenticated attacker to execute arbitrary code remotely.
Affected Versions:
OpenCMS version from 9.0.0 to 10.5.0
QID Detection Logic (unauthenticated)
:
This QID checks for vulnerable OpenCMS targets by sending a crafted xml payload as a POST request to '/cmisatom/cmis-online/query' endpoint. A vulnerable target tries to connect back to the scanner on a random port.
Please note that the detection relies on a callback and would require the target to be able to connect back to the scanner at a random port.
Successful exploitation of the vulnerability may allow a remote attacker to execute arbitrary code or read sensitive files on the target system .
CVEs related to QID 730984
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| OpenCMS 16 |
|