Alkacon OpenCms
cpe:2.3:a:alkacon:opencms:*:*:*:*:*:*:*
- >= 9, < 10.5.1
- >= 15, < 16
A cross-site scripting (XSS) vulnerability has been identified in Alkacon OpenCms versions prior to 16. The issue arises in the 'updateModelGroups.jsp' page, where user input is not properly sanitized, allowing for the injection of malicious scripts that could be executed in the context of the user's browser.
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
To reproduce this vulnerability, send a GET request to the 'updateModelGroups.jsp' page within the OpenCms application. Include a 'basePath' parameter with a value that contains a crafted script, such as an SVG image with an 'onload' event. The injected script will be executed when the response is loaded in the browser.
Users can update to OpenCms version 16 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.