{"id":"CVE-2023-6380","summary":"Open Redirect in Alkacon Software OpenCms","details":"Open redirect vulnerability has been found in the Open CMS product affecting versions 14 and 15 of the 'Mercury' template. An attacker could create a specially crafted URL and send it to a specific user to redirect them to a malicious site and compromise them. Exploitation of this vulnerability is possible due to the fact that there is no proper sanitization of the 'URI' parameter.","modified":"2026-08-12T03:51:14.209457264Z","published":"2023-12-13T10:54:35.693Z","database_specific":{"cwe_ids":["CWE-601"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/6xxx/CVE-2023-6380.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"14"},{"last_affected":"14"},{"introduced":"15"},{"last_affected":"15"}]}],"cna_assigner":"INCIBE"},"references":[{"type":"WEB","url":"https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-alkacon-software-opencms"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/6xxx/CVE-2023-6380.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-6380"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/alkacon/opencms-core","events":[{"introduced":"aa59361c26289e2d42a3fff1eb17dd95b579aa8a"},{"fixed":"773f1d2c19a861bb0ab2bbaab97bd3bae5a76063"}],"database_specific":{"extracted_events":[{"introduced":"14.0.0"},{"fixed":"16.0.0"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:alkacon:opencms:*:*:*:*:*:*:*:*"}}],"versions":["build_15_0_0","build_14_0_0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-6380.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}