Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cross-Site Scripting stored in Alkacon OpenCMS
Vulnerability Description
Two Cross-Site Scripting vulnerabilities have been discovered in Alkacon's OpenCMS affecting version 16, which could allow a user with sufficient privileges to create and modify web pages through the admin panel, can execute malicious JavaScript code, after inserting code in the “title” field.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Alkacon Software OpenCMS 跨站脚本漏洞
Vulnerability Description
Alkacon Software OpenCMS是德国Alkacon Software公司的一套开源的基于Java和XML的内容管理系统(CMS)。该系统支持模板引擎、所见即所得编辑器等。 Alkacon Software OpenCMS 16版本存在跨站脚本漏洞,该漏洞源于title字段存在存储型跨站脚本(XSS)漏洞。
CVSS Information
N/A
Vulnerability Type
N/A