CVE-2023-37602

CVSS v3.1 6.1 (Medium)
61% Progress
EPSS 0.18 % (55th)
0.18% Progress
Affected Products 1
Advisories 1

An arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2023-07-20 19:15:10
(14 months ago)
Updated Date
2023-07-31 16:51:03
(13 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Alkacon Opencms 15.0.0 cpe:2.3:a:alkacon:opencms:15.0.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...