{"id":"GHSA-w62v-q77r-66cc","summary":"Alkacon OpenCMS XSS via Mercury template","details":"Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing session.","aliases":["CVE-2023-6379"],"modified":"2025-06-20T16:29:49.541186Z","published":"2023-12-13T12:30:43Z","database_specific":{"github_reviewed_at":"2025-06-20T16:04:52Z","nvd_published_at":"2023-12-13T11:15:07Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-6379"},{"type":"WEB","url":"https://github.com/alkacon/opencms-core/commit/d965c18ac6d24ad75bfea272edb8b2efd4290afa"},{"type":"WEB","url":"https://github.com/alkacon/opencms-core"},{"type":"WEB","url":"https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-alkacon-software-opencms"}],"affected":[{"package":{"name":"org.opencms:opencms-core","ecosystem":"Maven","purl":"pkg:maven/org.opencms/opencms-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14.0.0"},{"fixed":"16.0.0"}]}],"versions":["14.0","15.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-w62v-q77r-66cc/GHSA-w62v-q77r-66cc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}]}