CVE-2019-13237
In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and…
Does this matter?
Lower severity and a low EPSS score (7.35%). Track it; it rarely justifies an emergency change on its own.
Description
In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and /system/workplace/admin/history/settings/index.jsp.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 7.35% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- alkacon/opencms apollo template
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/154281/Alkacon-OpenCMS-10.5.x-Local-File-Inclusion.htmlExploit, Third Party Advisory, VDB Entry
- https://aetsu.github.io/OpenCmsExploit, Third Party Advisory
- https://github.com/alkacon/opencms-core/commits/branch_10_5_xPatch
- http://packetstormsecurity.com/files/154281/Alkacon-OpenCMS-10.5.x-Local-File-Inclusion.htmlExploit, Third Party Advisory, VDB Entry
- https://aetsu.github.io/OpenCmsExploit, Third Party Advisory
- https://github.com/alkacon/opencms-core/commits/branch_10_5_xPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.