Executive brief
OpenCMS, a popular open-source content management system, contains a critical security flaw in its database import tool. An attacker can exploit this by uploading a specially crafted ZIP file, allowing them to potentially steal sensitive files from the server or disrupt operations. This could lead to a full compromise of the website's data and underlying infrastructure.
Technical details
OpenCMS v20 and prior versions are vulnerable to an XML External Entity (XXE) injection (CWE-611) within the Admin Import DB functionality. The vulnerability exists because the application's XML parser does not securely handle external entity references when processing the 'manifest.xml' file contained within a user-uploaded .zip archive. A remote, unauthenticated attacker can exploit this by submitting a malicious ZIP file to the import interface. Successful exploitation can lead to arbitrary file disclosure (OOB-XXE), server-side request forgery (SSRF), or denial-of-service. A patch has been identified in the alkacon/opencms-core repository (commit e3e41e5).
Affected products
- Alkacon Software OpenCMS v20 and earlier
Timeline
- 2026-05-05: disclosed
- 2026-05-05: advisory: NVD publication date