Alkacon OpenCMS XSS via homelink, workplaceresource, mode and query parameters
Low severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Jun 20, 2025
Description
Published by the National Vulnerability Database
Mar 19, 2015
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Jun 20, 2025
Last updated
Jun 20, 2025
Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms 9.5.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) homelink parameter to system/modules/org.opencms.workplace.help/jsptemplates/help_head.jsp, (2) workplaceresource parameter to system/workplace/locales/en/help/index.html, (3) path parameter to system/workplace/views/admin/admin-main.jsp, (4) mode parameter to system/workplace/views/explorer/explorer_files.jsp, or (5) query parameter in a search action to system/modules/org.opencms.workplace.help/elements/search.jsp.
References