Alkacon OpenCms
cpe:2.3:a:alkacon:opencms:*:*:*:*:*:*:*
- >= 9, < 10.5.1
A vulnerability allowing injection into Apache Solr has been identified in Alkacon OpenCms versions prior to 16. This issue arises from improper handling of XML data, specifically XML External Entity (XXE) processing, which can be exploited to read sensitive files from the server.
Exploitation of this vulnerability allows for unauthorized access to the Apache Solr query interface, where injected payloads could be executed, potentially leading to unauthorized data manipulation or access.
The vulnerability can be reproduced by sending a crafted HTTP GET request to the '/cmisatom/cmis-online/query' endpoint. The request must include a 'q' parameter that contains the injection payload, exploiting the Solr query parser.
Users are advised to update to OpenCms version 16 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.