Medium severity5.4NVD Advisory· Published Dec 13, 2023· Updated Jun 17, 2026
CVE-2023-6379
CVE-2023-6379
Description
Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing session.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.opencms:opencms-coreMaven | >= 14.0.0, < 16.0.0 | 16.0.0 |
Affected products
3- Alkacon/Open CMSv5Range: 14
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-w62v-q77r-66ccghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-6379ghsaADVISORY
- www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-alkacon-software-opencmsnvdThird Party AdvisoryWEB
- github.com/alkacon/opencms-core/commit/d965c18ac6d24ad75bfea272edb8b2efd4290afaghsaWEB
News mentions
0No linked articles in our index yet.