{"id":"GHSA-v3c3-qr6m-8m7m","summary":"Alkacon OpenCMS Improper Access Control via system/workplace/views/admin/admin-main.jsp","details":"system/workplace/views/admin/admin-main.jsp in Alkacon OpenCms before 6.2.2 does not restrict access to administrator functions, which allows remote authenticated users to (1) send broadcast messages to all users (/workplace/broadcast), (2) list all users (/accounts/users), (3) add webusers (/accounts/webusers/new), (4) upload database import and export files (/database/importhttp), (5) upload arbitrary program modules (/modules/modules_import), and (6) read the log file (/workplace/logfileview) by setting the appropriate value for the path parameter in a direct request to admin-main.jsp.","aliases":["CVE-2006-3935"],"modified":"2025-06-20T16:29:48.832158Z","published":"2022-05-01T07:13:46Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-06-20T15:33:36Z","nvd_published_at":"2006-07-31T22:04:00Z","cwe_ids":["CWE-284","CWE-862"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2006-3935"},{"type":"WEB","url":"https://github.com/alkacon/opencms-core/commit/8f1c04c5a16fe8d0bdbd13b65bf2a7b5cf100ff9"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27996"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28003"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28010"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28026"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28031"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28036"},{"type":"PACKAGE","url":"https://github.com/alkacon/opencms-core"},{"type":"WEB","url":"http://www.opencms.org/export/download/opencms/opencms_6.2.2_src.zip"}],"affected":[{"package":{"name":"org.opencms:opencms-core","ecosystem":"Maven","purl":"pkg:maven/org.opencms/opencms-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.2.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-v3c3-qr6m-8m7m/GHSA-v3c3-qr6m-8m7m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U"}]}