Launch Week Day 1: Announcing Security Design Review
HIGH 7.8 Maven

Alkacon OpenCMS CSV Injection via New User module

GHSA-q693-v7qf-p4xj · CVE-2019-11819

Published · Modified

Description

Alkacon OpenCMS v10.5.4 and before is affected by CSV (aka Excel Macro) Injection in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp) via the First Name or Last Name.

Ready to move

Start Securing

Free, no credit card | First findings in minutes