Description
An arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.
Remediation
References
https://www.exploit-db.com/exploits/51564
Related Vulnerabilities
CVE-2021-22135 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2022-24431 Vulnerability in npm package abacus-ext-cmdline
CVE-2022-43403 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2022-4245 Vulnerability in maven package org.codehaus.plexus:plexus-utils