CVE-2023-42343
Description
A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A stored XSS vulnerability in Alkacon OpenCms before 10.5.1 via cmis-online/type allows attackers to inject arbitrary web scripts.
A stored Cross-Site Scripting (XSS) vulnerability exists in Alkacon OpenCms versions prior to 10.5.1. The flaw occurs in the cmis-online/type parameter, where user-supplied input is not properly sanitized before being reflected back to users [1]. This allows an attacker to inject malicious HTML or JavaScript code.
To exploit the vulnerability, an attacker can craft a specially crafted URL or manipulate the parameter to include arbitrary script payloads. No authentication is required to trigger the XSS, but the victim must open the malicious link. The attack surface is broad as the parameter is used in standard OpenCms functionality related to CMIS integration [4].
Successful exploitation enables an attacker to execute arbitrary JavaScript in the context of the victim's browser. This can lead to session hijacking, cookie theft, defacement, or redirection to malicious sites. The impact is limited to the browser session but can compromise user accounts and sensitive data.
Alkacon has released OpenCms version 10.5.1 which addresses this vulnerability. Users are strongly advised to upgrade to the latest version to mitigate the risk. No workarounds have been publicly documented.
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.opencms:opencms-coreMaven | < 16.0 | 16.0 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.