CVE-2024-42699

Publication date

2025-04-21 00:00:00

Family

mitre

State

PUBLISHED

Description

Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to inject javascript payload via image title sub-field in the image field