CVE-2019-11818

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
08/05/2019
Last modified:
08/05/2019

Description

Alkacon OpenCMS v10.5.4 and before is affected by stored cross site scripting (XSS) in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp). This allows an attacker to insert arbitrary JavaScript as user input (First Name or Last Name), which will be executed whenever the affected snippet is loaded.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:alkacon:opencms:*:*:*:*:*:*:*:* 10.5.4 (including)