Launch Week Day 1: Announcing Security Design Review
UNKNOWN Maven

Alkacon OpenCMS XSS via New User module

GHSA-c8j6-gqq8-4prj · CVE-2019-11818

Published · Modified

Description

Alkacon OpenCMS v10.5.4 and before is affected by stored cross site scripting (XSS) in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp). This allows an attacker to insert arbitrary JavaScript as user input (First Name or Last Name), which will be executed whenever the affected snippet is loaded.

Ready to move

Start Securing

Free, no credit card | First findings in minutes