Alkacon OpenCMS XSS via New User module
Low severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jun 20, 2025
Description
Published by the National Vulnerability Database
May 8, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jun 20, 2025
Last updated
Jun 20, 2025
Alkacon OpenCMS v10.5.4 and before is affected by stored cross site scripting (XSS) in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp). This allows an attacker to insert arbitrary JavaScript as user input (First Name or Last Name), which will be executed whenever the affected snippet is loaded.
References