Vulnerability Description
In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and /system/workplace/admin/history/settings/index.jsp.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alkacon | Opencms Apollo Template | 10.5.4 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/154281/Alkacon-OpenCMS-10.5.x-Local-File-InExploitThird Party AdvisoryVDB Entry
- https://aetsu.github.io/OpenCmsExploitThird Party Advisory
- https://github.com/alkacon/opencms-core/commits/branch_10_5_xPatch
- http://packetstormsecurity.com/files/154281/Alkacon-OpenCMS-10.5.x-Local-File-InExploitThird Party AdvisoryVDB Entry
- https://aetsu.github.io/OpenCmsExploitThird Party Advisory
- https://github.com/alkacon/opencms-core/commits/branch_10_5_xPatch
FAQ
What is CVE-2019-13237?
CVE-2019-13237 is a vulnerability with a CVSS score of 4.3 (MEDIUM). In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp...
How severe is CVE-2019-13237?
CVE-2019-13237 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-13237?
Check the references section above for vendor advisories and patch information. Affected products include: Alkacon Opencms Apollo Template.