Alkacon OpenCMS
0 remedies
cpe:2.3:a:alkacon:opencms:*:*:*:*:*:*:*
0 remedies
A cross-site scripting (XSS) vulnerability has been identified in Alkacon OpenCMS version 17.0. This issue allows remote attackers to inject JavaScript payloads through the image title sub-field of the image field when creating or modifying articles.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the article.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.