CVE-2013-4600: Alkacon Opencms

Medium severity, CVSS 4.3. EPSS: 1.9% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms before 8.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to system/workplace/views/admin/admin-main.jsp or the (2) requestedResource parameter to system/login/index.html.

Affected products

  • Alkacon Opencms: up to and including 8.5.1; version 6.0.0 only; version 6.0.2 only; version 6.0.3 only; version 6.0.4 only; version 6.2 only; …

Published 2013-08-09. Last modified 2026-06-16.