Launch Week Day 1: Announcing Security Design Review
UNKNOWN Maven

Alkacon OpenCMS XSS via searchfilter parameter in system/workplace/admin/workplace/sessions.jsp

GHSA-4r3g-w24c-gpr6 · CVE-2008-1753

Published · Modified

Description

Cross-site scripting (XSS) vulnerability in system/workplace/admin/workplace/sessions.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the searchfilter parameter, a different vector than CVE-2008-1510.

Ready to move

Start Securing

Free, no credit card | First findings in minutes