PT-2024-36493 · Alkacon · Opencms

Miguel Segovia Gil

·

Published

2024-05-30

·

Updated

2024-05-30

·

CVE-2024-5520

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Alkacon's OpenCMS version 16
Description Two Cross-Site Scripting issues have been discovered in Alkacon's OpenCMS, which could allow a user with sufficient privileges to create and modify web pages through the admin panel to execute malicious JavaScript code after inserting code in the title field. Another issue allows users with the roles of gallery editor or VFS resource manager to upload images in the .svg format containing JavaScript code, which will be executed when another user accesses the image.
Recommendations For version 16, consider disabling the ability to insert code in the title field and restrict the upload of .svg images until a patch is available. Restrict access to the admin panel and limit the roles of gallery editor and VFS resource manager to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-5520
GHSA-VG6X-PCHQ-98MG

Affected Products

Opencms