{"id":"GHSA-h75c-f2xx-9vxv","summary":"OpenCMS Cross-Site Scripting vulnerability","details":"Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to inject javascript payload via image title sub-field in the image field","aliases":["CVE-2024-42699"],"modified":"2025-04-21T17:12:01.740920Z","published":"2025-04-21T15:31:25Z","database_specific":{"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2025-04-21T16:33:10Z","nvd_published_at":"2025-04-21T15:15:58Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-42699"},{"type":"WEB","url":"https://github.com/Sidd545-cr/CVE/blob/main/CVE-2024-42699%20-%20Stored%20XSS%20in%20image%20title.pdf"},{"type":"PACKAGE","url":"https://github.com/alkacon/opencms-core"}],"affected":[{"package":{"name":"org.opencms:opencms-core","ecosystem":"Maven","purl":"pkg:maven/org.opencms/opencms-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"17.0"}]}],"versions":["10.0.0","10.0.1","10.5.0","10.5.1","10.5.2","10.5.3","10.5.4","11.0.0","11.0.1","11.0.2","12.0","13.0","14.0","15.0","16.0","17.0","8.0.1","8.0.2","8.0.3","8.0.3-rev","8.0.3.1","8.0.4","8.5.0","8.5.1","8.5.2","9.0.0","9.0.1","9.5.0","9.5.1","9.5.2","9.5.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-h75c-f2xx-9vxv/GHSA-h75c-f2xx-9vxv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P"}]}