GHSA-4fg8-5hwc-wg5v
Dashboard / Vulnerabilities / GHSA-4fg8-5hwc-wg5v
Summary: Alkacon OpenCMS XSS via searchfilter or listSearchFilter parameter
Details: Cross-site scripting (XSS) vulnerability in system/workplace/admin/accounts/users_list.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the (1) searchfilter or (2) listSearchFilter parameter.
References: https://nvd.nist.gov/vuln/detail/CVE-2008-1510, https://github.com/alkacon/opencms-core/commit/49c5beded65bf0232cab61b1299b85dee9ae2014, https://exchange.xforce.ibmcloud.com/vulnerabilities/41390, https://github.com/alkacon/opencms-core, http://securityreason.com/securityalert/3777
Affected packages
Package
Name: org.opencms:opencms-core
Purl: pkg:maven/org.opencms/opencms-core
Affected ranges
Type: ECOSYSTEM
Events:
