
CVE-2023-42344 Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet. https://www.cve.org/CVERecord?id=CVE-2023-42344
Post summary
The text announces CVE-2023-42344 in Alkacon OpenCms, detailing that unauthenticated attackers can exploit an XXE vulnerability in the Chemistry servlet to retrieve sensitive data.

