Junglewise Threat Intelligence

CVE-2023-42343: Alkacon OpenCms XSS in cmis-online/type

CVE-2023-42343 · Severity: medium · CVSS 6.1 · Published 2026-05-08

Technologies: Alkacon OpenCms, org.opencms:opencms-core (Maven). Vendors: Alkacon, Maven.

Executive brief

Alkacon OpenCms, a popular enterprise content management system, is vulnerable to a security flaw that allows attackers to inject malicious scripts into web pages. By tricking a user into clicking a link or visiting a crafted page, an attacker could steal login session information or perform actions on behalf of the user. This could lead to unauthorized access to the management console or the compromise of sensitive customer data.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in Alkacon OpenCms versions prior to 16.0. The vulnerability is located in the 'cmis-online/type' endpoint, where user-supplied input is improperly neutralized before being rendered in the server's response. An unauthenticated remote attacker can exploit this by persuading a user to visit a malicious URL. Successful exploitation allows the execution of arbitrary JavaScript in the victim's browser, potentially leading to session hijacking (via cookie theft) or unauthorized actions within the CMS. The issue was addressed in version 16.0.

Affected products

  • Alkacon OpenCms < 16.0

Timeline

  • 2023-11-21: other: Initial research published by watchTowr Labs
  • 2026-05-08: disclosed: CVE-2023-42343 published
  • 2026-05-08: advisory: GitHub Advisory published

References

Related threats