Medium severity6.4NVD Advisory· Published May 30, 2024· Updated Jun 17, 2026
CVE-2024-5520
CVE-2024-5520
Description
Two Cross-Site Scripting vulnerabilities have been discovered in Alkacon's OpenCMS affecting version 16, which could allow a user with sufficient privileges to create and modify web pages through the admin panel, can execute malicious JavaScript code, after inserting code in the “title” field.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.opencms:opencms-coreMaven | >= 16.0, < 17.0 | 17.0 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-vg6x-pchq-98mgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-5520ghsaADVISORY
- www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-stored-alkacon-opencmsnvdThird Party AdvisoryWEB
- github.com/alkacon/opencms-core/commit/b05a5aca0f2b03042ddf2b2bb45fe2243a4084a7ghsaWEB
News mentions
0No linked articles in our index yet.