VYPR

Opencms Apollo Template

by Alkacon

CVEs (3)

  • CVE-2019-13235MedAug 27, 2019
    risk 0.43cvss 6.1epss 0.03

    In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.

  • CVE-2019-13234MedAug 27, 2019
    risk 0.43cvss 6.1epss 0.03

    In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.

  • CVE-2019-13237MedAug 27, 2019
    risk 0.32cvss 4.3epss 0.07

    In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and…