Skip to content

Commit

Permalink
Update CVE-2023-42344.yaml
Browse files Browse the repository at this point in the history
  • Loading branch information
DhiyaneshGeek authored Feb 22, 2024
1 parent 60ac59c commit cee7822
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions http/cves/2023/CVE-2023-42344.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ id: CVE-2023-42344

info:
name: OpenCMS - Unauthenticated XXE
author: x0xr2r
author: 0xr2r
severity: high
description: |
users can execute code without authentication. An attacker can execute malicious requests on the OpenCms server. When the requests are successful vulnerable OpenCms can be exploited resulting in an unauthenticated XXE vulnerability. Based on research OpenCMS versions from 9.0.0 to 10.5.0 are vulnerable.
Expand Down Expand Up @@ -36,4 +36,4 @@ http:
- "root:.*:0:0:"
- "invalidArgument"
condition: and
# digest: 490a0046304402207109561f9ee225ddc24e0e2428763262bbd09665f2d2e30980f46c87af7476fd02206d213db222bf432261211cadb7e9cdc0f4431ad34f41a444becca4917fa9d2ec:922c64590222798bb761d5b6d8e72950
# digest: 490a0046304402207109561f9ee225ddc24e0e2428763262bbd09665f2d2e30980f46c87af7476fd02206d213db222bf432261211cadb7e9cdc0f4431ad34f41a444becca4917fa9d2ec:922c64590222798bb761d5b6d8e72950

0 comments on commit cee7822

Please sign in to comment.