PT-2025-17320 · Alkacon · Alkacon Opencms

Published

2025-04-18

·

Updated

2025-04-18

·

CVE-2024-41447

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Alkacon OpenCMS version 17.0
Description A stored cross-site scripting (XSS) issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the author parameter under the Create/Modify article function.
Recommendations For Alkacon OpenCMS version 17.0, consider disabling the Create/Modify article function until a patch is available to prevent exploitation of the stored XSS issue. Restrict access to the author parameter to minimize the risk of arbitrary web script execution.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-41447
GHSA-VQ95-6X79-QV8J

Affected Products

Alkacon Opencms