Local file inclusion allows unauthorized access to internal resources in Alkacon OpenCms
Moderate severity
GitHub Reviewed
Published
Nov 12, 2019
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Aug 27, 2019
Reviewed
Nov 12, 2019
Published to the GitHub Advisory Database
Nov 12, 2019
Last updated
Feb 1, 2023
In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and /system/workplace/admin/history/settings/index.jsp.
References