PT-2026-20772 · Alkacon · Alkacon Opencms
Published
2026-02-19
·
Updated
2026-02-19
·
CVE-2026-2735
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Alkacon OpenCms version 18.0
Description
A stored Cross-Site Scripting (XSS) issue exists in Alkacon OpenCms version 18.0. The issue occurs because user-supplied data is not adequately validated when a POST request is sent to the following API endpoint:
/blog/new-article/org.opencms.ugc.CmsUgcEditService.gwt. The vulnerable parameter is text. This allows an attacker to inject malicious scripts that will be executed in the context of other users' browsers.Recommendations
Apply input validation to the
text parameter when processing POST requests to the /blog/new-article/org.opencms.ugc.CmsUgcEditService.gwt endpoint.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alkacon Opencms