CVE-2023-42344

Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet.
Configurations

No configuration.

History

No history.

Information

Published : 2026-05-08 05:16

Updated : 2026-06-17 06:23


NVD link : CVE-2023-42344

Mitre link : CVE-2023-42344

CVE.ORG link : CVE-2023-42344


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference