Medium severity5.4NVD Advisory· Published Apr 18, 2025· Updated Jun 17, 2026
CVE-2024-41447
CVE-2024-41447
Description
A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the author parameter under the Create/Modify article function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.opencms:opencms-coreMaven | <= 17.0 | — |
Affected products
3Patches
Vulnerability mechanics
References
4- www.exploit-db.com/exploits/52209nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-vq95-6x79-qv8jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-41447ghsaADVISORY
- github.com/Sidd545-cr/CVE/blob/main/CVE-2024-41447%20-%20Stored%20XSS%20in%20author%20field.pdfghsaWEB
News mentions
0No linked articles in our index yet.