Description
An arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.
Remediation
References
https://www.exploit-db.com/exploits/51564
Related Vulnerabilities
CVE-2018-16489 Vulnerability in maven package org.webjars.npm:just-extend
CVE-2022-31183 Vulnerability in maven package co.fs2:fs2-io_sjs1_2.12
CVE-2022-23461 Vulnerability in maven package org.webjars.npm:jodit
CVE-2023-3691 Vulnerability in maven package org.webjars.npm:layui
CVE-2023-47324 Vulnerability in maven package org.silverpeas.core:silverpeas-core-rs