Количество 2
Количество 2
CVE-2019-11818
Alkacon OpenCMS v10.5.4 and before is affected by stored cross site scripting (XSS) in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp). This allows an attacker to insert arbitrary JavaScript as user input (First Name or Last Name), which will be executed whenever the affected snippet is loaded.
GHSA-c8j6-gqq8-4prj
Alkacon OpenCMS XSS via New User module
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-11818 Alkacon OpenCMS v10.5.4 and before is affected by stored cross site scripting (XSS) in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp). This allows an attacker to insert arbitrary JavaScript as user input (First Name or Last Name), which will be executed whenever the affected snippet is loaded. | CVSS3: 6.1 | 0% Низкий | почти 7 лет назад | |
GHSA-c8j6-gqq8-4prj Alkacon OpenCMS XSS via New User module | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу