A stored cross-site scripting (XSS) vulnerability in alkacon-OpenCMS v11.0.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field under the Upload Image module.
[
{
"source": "https://github.com/alkacon/opencms-core/commit/21bfbeaf6b038e2c03bb421ce7f0933dd7a7633e",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"function_hash": "50429665448565272100370540995517851942",
"length": 520.0
},
"target": {
"file": "src-gwt/org/opencms/ade/galleries/client/ui/CmsResultItemWidget.java",
"function": "generateTooltipHtml"
},
"id": "CVE-2023-31544-35e7becd"
},
{
"source": "https://github.com/alkacon/opencms-core/commit/21bfbeaf6b038e2c03bb421ce7f0933dd7a7633e",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"91927551225445991945862037228577807679",
"63589510644510606645000682509175811155",
"12985639700293883131514078984697374378",
"321412344255156343060728942899010204069",
"29709425315528441144474906284849667035",
"176218194143383261642092853321414469115",
"34124468324456792625486543789398795913",
"167988049204659269185275283547638679337",
"144622807873684244434351208354175467958",
"171982460249227650780292751700688469575",
"252697926200555455118742149712327222353",
"201650612098034476215297017149903619819",
"169069705265304883125399644935528488412",
"298412032077307482883387501341329868144",
"44764525019660168099488567987899443185",
"8972207384109697615279536948673426749",
"207108137154084279567484555127082245488",
"61922241573248349211335395071226610392"
]
},
"target": {
"file": "src-gwt/org/opencms/ade/galleries/client/ui/CmsResultItemWidget.java"
},
"id": "CVE-2023-31544-3c69bf3e"
}
]