First published: Wed Dec 13 2023(Updated: )
Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing session.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
Alkacon OpenCMS | >=14.0.0<16.0.0 |
The vulnerabilities have been fixed in OpenCms version 16.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6379 is considered a high severity cross-site scripting (XSS) vulnerability.
To fix CVE-2023-6379, update Alkacon Open CMS to version 16.0.0 or later.
CVE-2023-6379 affects versions 14 and 15 of the Alkacon Open CMS 'Mercury' template.
Yes, CVE-2023-6379 can be exploited by an unauthenticated remote attacker.
CVE-2023-6379 enables cross-site scripting (XSS) attacks that can interfere with a user's browser session.