CVE-2019-11818
Last modified
CVE-2019-11818 is a vulnerability of currently unknown severity. Alkacon OpenCMS v10.5.4 and before is affected by stored cross site scripting (XSS) in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp). This allows an attacker to insert arbitrary JavaScript as user input (First Name or Last Name), which will be executed whenever the affected snippet is loaded.. EPSS estimates a 0.77% chance of exploitation in the next 30 days.
Description
Alkacon OpenCMS v10.5.4 and before is affected by stored cross site scripting (XSS) in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp). This allows an attacker to insert arbitrary JavaScript as user input (First Name or Last Name), which will be executed whenever the affected snippet is loaded.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Alkacon | Opencms | <= 10.5.4 |
References
- https://github.com/alkacon/opencms-core/issues/635Exploit, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2019/04/30/3Exploit, Mailing List, Third Party Advisory
- https://github.com/alkacon/opencms-core/issues/635Exploit, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2019/04/30/3Exploit, Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-11818?
How severe is CVE-2019-11818?
How do I fix CVE-2019-11818?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-11811An issue was discovered in the Linux kernel before 5.0.4. Th…7
- CVE-2019-11812A persistent XSS issue was discovered in app/View/Helper/Com…
- CVE-2019-11813An issue was discovered in app/View/Elements/Events/View/val…
- CVE-2019-11814An issue was discovered in app/webroot/js/misp.js in MISP be…
- CVE-2019-11815An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.…8.1
- CVE-2019-11816Incorrect access control in the WebUI in OPNsense before ver…7.2
- CVE-2019-11819Alkacon OpenCMS v10.5.4 and before is affected by CSV (aka E…
- CVE-2019-1182A remote code execution vulnerability exists in Remote Deskt…9.8
- CVE-2019-11820Information exposure through process environment vulnerabili…5.5
- CVE-2019-11821SQL injection vulnerability in synophoto_csPhotoDB.php in Sy…9.8
- CVE-2019-11822Relative path traversal vulnerability in SYNO.PhotoStation.F…6.5
- CVE-2019-11823CRLF injection vulnerability in Network Center in Synology R…7.5
Are you affected by CVE-2019-11818?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
