CVE-2008-1510

Description

Cross-site scripting (XSS) vulnerability in system/workplace/admin/accounts/users_list.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the (1) searchfilter or (2) listSearchFilter parameter.

Risk Information

Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
0.564

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2008-1753,CVE-2008-1510,CVE-2008-1045 are fixed in Opencms-opencms-core 7.0.4Windows
Vulnerabilities CVE-2008-1753,CVE-2008-1510,CVE-2008-1045 are fixed in Opencms-opencms-core for Linux 7.0.4Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234