CVE-2019-13237: Alkacon Opencms Apollo Template

Medium severity, CVSS 4.3. EPSS: 7.3% chance of exploitation in the next 30 days.

In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and /system/workplace/admin/history/settings/index.jsp.

Affected products

  • Alkacon Opencms Apollo Template: version 10.5.4 only; version 10.5.5 only

Published 2019-08-27. Last modified 2026-06-17.