CVE-2013-4600: Alkacon Opencms
Medium severity, CVSS 4.3. EPSS: 1.9% chance of exploitation in the next 30 days.
Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms before 8.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to system/workplace/views/admin/admin-main.jsp or the (2) requestedResource parameter to system/login/index.html.
Affected products
- Alkacon Opencms: up to and including 8.5.1; version 6.0.0 only; version 6.0.2 only; version 6.0.3 only; version 6.0.4 only; version 6.2 only; …
Published 2013-08-09. Last modified 2026-06-16.