UNKNOWN Maven
Alkacon OpenCMS XSS via searchfilter or listSearchFilter parameter
GHSA-4fg8-5hwc-wg5v · CVE-2008-1510
Published · Modified
Description
Cross-site scripting (XSS) vulnerability in system/workplace/admin/accounts/users_list.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the (1) searchfilter or (2) listSearchFilter parameter.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2008-1510
- WEB https://github.com/alkacon/opencms-core/commit/49c5beded65bf0232cab61b1299b85dee9ae2014
- WEB https://exchange.xforce.ibmcloud.com/vulnerabilities/41390
- PACKAGE https://github.com/alkacon/opencms-core
- WEB http://securityreason.com/securityalert/3777
Ready to move
Start Securing
Free, no credit card | First findings in minutes