First published: Tue Aug 27 2019(Updated: )
In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and /system/workplace/admin/history/settings/index.jsp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Alkacon OpenCms Apollo Template | =10.5.4 | |
Alkacon OpenCms Apollo Template | =10.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13237 has a high severity rating due to its potential to allow local file inclusion and unauthorized access to sensitive server resources.
To fix CVE-2019-13237, you should upgrade to a patched version of Alkacon OpenCms, ensuring that all vulnerable JSP resources are secured.
CVE-2019-13237 affects Alkacon OpenCms versions 10.5.4 and 10.5.5.
The impact of CVE-2019-13237 is that an attacker can exploit multiple resources to access sensitive server files and potentially compromise the system.
Yes, there are known exploits for CVE-2019-13237 that leverage the local file inclusion vulnerability to access unauthorized server resources.