Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 Maven

Alkacon OpenCms is vulnerable to XXE when the <!DOCTYPE> refers to an external host

GHSA-pj6p-9p8x-5mfc · CVE-2023-42346

Published · Modified

Description

Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host.

Ready to move

Start Securing

Free, no credit card | First findings in minutes