GHSA-w3v2-vfrj-j9g8
Dashboard / Vulnerabilities / GHSA-w3v2-vfrj-j9g8
Summary: Alkacon Open CMS XSS via Logfile Viewer Settings function
Details: Cross-site scripting (XSS) vulnerability in the Logfile Viewer Settings function in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote attackers to inject arbitrary web script or HTML via the filePath.0 parameter in a save action, a different vector than CVE-2008-1045.
References: https://nvd.nist.gov/vuln/detail/CVE-2008-1300, https://github.com/alkacon/opencms-core/commit/7b73b5559c1b025dfe0f7b38ed4119c25b9df409, https://github.com/alkacon/opencms-core, http://securityreason.com/securityalert/3731
Affected packages
Package
Name: org.opencms:opencms-core
Purl: pkg:maven/org.opencms/opencms-core
Affected ranges
Type: ECOSYSTEM
Events:
