PT-2023-7058 · Opencms · Opencms

CVE-2023-42344

·

Published

2023-08-07

·

Updated

2026-05-10

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Alkacon OpenCms versions prior to 10.5.1
Description Remote unauthenticated attackers can obtain sensitive information or execute arbitrary code by sending a specially crafted POST request. This is possible due to improper restriction of XML references to external objects, leading to an XML External Entity (XXE) attack—a technique where an application processes external entities within an XML document—targeting the 'cmis-online/query' endpoint on a Chemistry servlet.
Recommendations Update to version 10.5.1 or later.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-08080
CVE-2023-42344
GHSA-RCC6-6Q2F-M2CW

Affected Products

Opencms