Description
Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to inject arbitrary web script or HTML via a malicious SVG image.
Remediation
References
https://github.com/alkacon/opencms-core/issues/587
https://www.exploit-db.com/exploits/44392/
Related Vulnerabilities
CVE-2022-23541 Vulnerability in npm package jsonwebtoken
CVE-2022-2421 Vulnerability in maven package org.webjars.npm:socket.io-parser
CVE-2022-31069 Vulnerability in npm package @ffdc/nestjs-proxy
CVE-2023-37259 Vulnerability in npm package matrix-react-sdk
CVE-2022-29258 Vulnerability in maven package org.xwiki.platform:xwiki-platform-filter-ui