Vulnerabilities
Vulnerable Software
Alkacon:  >> Opencms  >> 17.0.0  Security Vulnerabilities
Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to inject javascript payload via image title sub-field in the image field
CVSS Score
6.5
EPSS Score
0.002
Published
2025-04-21
A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the image parameter under the Create/Modify article function.
CVSS Score
5.4
EPSS Score
0.0
Published
2025-04-21
A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the author parameter under the Create/Modify article function.
CVSS Score
5.4
EPSS Score
0.0
Published
2025-04-18


Contact Us

Shodan ® - All rights reserved