PT-2025-17435 · Alkacon · Alkacon Opencms

Published

2025-04-21

·

Updated

2025-04-24

·

CVE-2024-41446

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Alkacon OpenCMS version 17.0
Description A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the image parameter under the Create/Modify article function.
Recommendations For Alkacon OpenCMS version 17.0, consider disabling the Create/Modify article function until a patch is available, or restrict access to the image parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-41446
GHSA-7M3W-M5G3-CC88

Affected Products

Alkacon Opencms