CVE-2023-37602
Description
An arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Alkacon OpenCMS v15.0 suffers from an arbitrary file upload vulnerability in the /workplace#!explorer component, allowing authenticated attackers to execute arbitrary code via a crafted PNG file.
Vulnerability
Overview
CVE-2023-37602 describes an arbitrary file upload vulnerability in Alkacon OpenCMS v15.0, specifically within the /workplace#!explorer component [1]. The official description notes that an attacker can upload a crafted PNG file to achieve arbitrary code execution [2]. This indicates insufficient validation of file content or upload permissions, enabling the upload of files that may contain executable code, such as PHP or JSP scripts disguised as PNG images.
Attack
Vector and Prerequisites
An attacker must first authenticate to the OpenCMS instance to access the explorer component [3]. The exploitation process involves navigating to the file upload functionality and selecting a specially crafted file (e.g., a PNG with embedded PHP code) [2]. No additional privileges beyond standard upload rights are required, making this a medium-complexity attack that could be executed by users with limited access.
Impact
Successful exploitation allows arbitrary code execution on the underlying server in the context of the web application [2]. This can lead to full compromise of the content management system, including data exfiltration, site defacement, or lateral movement to internal networks.
Mitigation
Status
As of the publication date (2023-07-20), no official patch has been announced. Users should review the vendor's GitHub repository for updates [1] and consider restricting file upload capabilities to trusted users or implementing additional file content validation.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.opencms:opencms-coreMaven | <= 15.0 | — |
Affected products
2- Alkacon/OpenCMSdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-ghg2-3w9x-9599ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-37602ghsaADVISORY
- www.exploit-db.com/exploits/51564ghsaWEB
News mentions
0No linked articles in our index yet.