PT-2018-18639 · Alkacon · Alkacon Opencms

Sureshbabu Narvaneni

·

Publicado

2018-03-20

·

Atualizado

2018-04-13

·

CVE-2018-8815

CVSS v3.1

4.6

Média

VetorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Alkacon OpenCMS version 10.5.3
Description A cross-site scripting (XSS) issue exists in the gallery function, allowing remote attackers to inject arbitrary web script or HTML via a malicious SVG image. This can be exploited by attackers to execute malicious code on the victim's browser.
Recommendations For Alkacon OpenCMS version 10.5.3, consider disabling the gallery function until a patch is available to prevent exploitation of the XSS vulnerability. Restrict access to the gallery module to minimize the risk of exploitation. Avoid using the gallery function with untrusted input until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-8815

Produtos afetados

Alkacon Opencms