CVE Published: 13/12/2023 |
CVE Updated: 01/10/2024 |
CVE Year: 2023 Source: INCIBE |
Vendor: Alkacon |
Product: Open CMS Status : PUBLISHED
CVE-2023-6379 Description
Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the \'Mercury\' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing session.
Metrics
CVSS Version: 3.1 |
Base Score: 5.4 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N