Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2019-13234

Disclosure Date: August 27, 2019 (last updated November 27, 2024)
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.
0
Attacker Value
Unknown

CVE-2019-13237

Disclosure Date: August 27, 2019 (last updated November 27, 2024)
In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and /system/workplace/admin/history/settings/index.jsp.
Attacker Value
Unknown

CVE-2019-13235

Disclosure Date: August 27, 2019 (last updated November 27, 2024)
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
0
Attacker Value
Unknown

CVE-2019-13236

Disclosure Date: August 27, 2019 (last updated November 27, 2024)
In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface.
0