logo

OpenCMS Unauthenticated XXE Vulnerability (CVE-2023-42344)

ID: 125efea1-b825-5155-b2d3-873db9223973

STIX ID: report--125efea1-b825-5155-b2d3-873db9223973

Feed Name: Qualys Blog

Threat Score
70/100

Date Published: 2023-12-08

Date Updated: 2026-04-28

Author: Sheela Sarva

...
...

Qualys details CVE-2023-42344, a critical unauthenticated XXE vulnerability in OpenCms (<=10.5.0) that allows attackers to send crafted POST requests to exfiltrate files (PoC shows /etc/passwd). Qualys provides detection via QID 150773 and recommends upgrading to OpenCms 10.5.1 or later to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.