Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rcc6-6q2f-m2cw | Alkacon OpenCms allows remote unauthenticated attackers to obtain sensitive information |
Tue, 12 May 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Unauthenticated XXE in Alkacon OpenCms Chemistry Servlet |
Mon, 11 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Alkacon
Alkacon opencms |
|
| Vendors & Products |
Alkacon
Alkacon opencms |
Sat, 09 May 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Information Disclosure via XXE in Alkacon OpenCms Chemistry Servlet |
Fri, 08 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Information Disclosure via XXE in Alkacon OpenCms Chemistry Servlet |
Fri, 08 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XXE Vulnerability in Alkacon OpenCms Allowing Remote Retrieval of Sensitive Information |
Fri, 08 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
cvssV3_1
|
Fri, 08 May 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XXE Vulnerability in Alkacon OpenCms Allowing Remote Retrieval of Sensitive Information | |
| Weaknesses | CWE-611 |
Fri, 08 May 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-08T14:36:11.494Z
Reserved: 2023-09-08T00:00:00.000Z
Link: CVE-2023-42344
Updated: 2026-05-08T14:31:07.325Z
Status : Deferred
Published: 2026-05-08T05:16:09.560
Modified: 2026-05-08T15:58:49.383
Link: CVE-2023-42344
No data.
OpenCVE Enrichment
Updated: 2026-05-12T14:45:17Z
Github GHSA