VYPR
Medium severity6.1NVD Advisory· Published May 8, 2026· Updated May 8, 2026

CVE-2023-42343

CVE-2023-42343

Description

A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A stored XSS vulnerability in Alkacon OpenCms before 10.5.1 via cmis-online/type allows attackers to inject arbitrary web scripts.

A stored Cross-Site Scripting (XSS) vulnerability exists in Alkacon OpenCms versions prior to 10.5.1. The flaw occurs in the cmis-online/type parameter, where user-supplied input is not properly sanitized before being reflected back to users [1]. This allows an attacker to inject malicious HTML or JavaScript code.

To exploit the vulnerability, an attacker can craft a specially crafted URL or manipulate the parameter to include arbitrary script payloads. No authentication is required to trigger the XSS, but the victim must open the malicious link. The attack surface is broad as the parameter is used in standard OpenCms functionality related to CMIS integration [4].

Successful exploitation enables an attacker to execute arbitrary JavaScript in the context of the victim's browser. This can lead to session hijacking, cookie theft, defacement, or redirection to malicious sites. The impact is limited to the browser session but can compromise user accounts and sensitive data.

Alkacon has released OpenCms version 10.5.1 which addresses this vulnerability. Users are strongly advised to upgrade to the latest version to mitigate the risk. No workarounds have been publicly documented.

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.opencms:opencms-coreMaven
< 16.016.0

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.