Miggo Logo

CVE-2023-37602: Alkacon OpenCMS arbitrary file upload vulnerability

6.1

CVSS Score
3.1

Basic Information

EPSS Score
0.55832%
Published
7/20/2023
Updated
11/10/2023
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
org.opencms:opencms-coremaven<= 15.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

*n *r*itr*ry *il* uplo** vuln*r**ility in t** *ompon*nt /workpl***#!*xplor*r o* *lk**on Op*n*MS v**.* *llows *tt**k*rs to *x**ut* *r*itr*ry *o** vi* uplo**in* * *r**t** PN* *il*.

Reasoning

No *n*lysis *v*il**l*