CVE-2023-42344

Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet.
Configurations

No configuration.

History

08 May 2026, 15:16

Type Values Removed Values Added
CWE CWE-611
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3
References
  • () https://github.com/projectdiscovery/nuclei-templates/issues/8864 -

08 May 2026, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-08 05:16

Updated : 2026-05-08 15:58


NVD link : CVE-2023-42344

Mitre link : CVE-2023-42344

CVE.ORG link : CVE-2023-42344


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference