CVE-2024-41446
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Apr 21, 2025
Updated: Apr 24, 2025
CWE ID 79
Summary
CVE-2024-41446 is a stored cross-site scripting (XSS) vulnerability affecting Alkacon OpenCMS version 17.0. This issue allows attackers to inject arbitrary web scripts or HTML code into the image parameter of the Create/Modify article function. Successful exploitation enables attackers to execute malicious scripts in the context of the targeted user, potentially leading to unauthorized access, data theft, or website defacement. Users are advised to upgrade to a patched version as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Alkacon Software GmbH & Co. KG