QID 981631

QID 981631: Java (maven) Security Update for org.opencms:opencms-core (GHSA-7qqr-3pj3-q2f5)

In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-7qqr-3pj3-q2f5 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981631

    Software Advisories
    Advisory ID Software Component Link
    GHSA-7qqr-3pj3-q2f5 org.opencms:opencms-core URL Logo github.com/advisories/GHSA-7qqr-3pj3-q2f5