PT-2018-18639 · Alkacon · Alkacon Opencms
Sureshbabu Narvaneni
·
Published
2018-03-20
·
Updated
2018-04-13
·
CVE-2018-8815
CVSS v3.1
4.6
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Alkacon OpenCMS version 10.5.3
Description
A cross-site scripting (XSS) issue exists in the gallery function, allowing remote attackers to inject arbitrary web script or HTML via a malicious SVG image. This can be exploited by attackers to execute malicious code on the victim's browser.
Recommendations
For Alkacon OpenCMS version 10.5.3, consider disabling the gallery function until a patch is available to prevent exploitation of the XSS vulnerability. Restrict access to the gallery module to minimize the risk of exploitation. Avoid using the gallery function with untrusted input until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alkacon Opencms