Description
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.
Remediation
References
http://packetstormsecurity.com/files/154298/Alkacon-OpenCMS-10.5.x-Cross-Site-Scripting.html
https://aetsu.github.io/OpenCms
https://github.com/alkacon/apollo-template/commits/branch_10_5_x
Related Vulnerabilities
CVE-2020-7642 Vulnerability in maven package org.webjars.bowergithub.afarkas:lazysizes
CVE-2022-22880 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core
CVE-2021-43571 Vulnerability in npm package starkbank-ecdsa
CVE-2022-27772 Vulnerability in maven package org.springframework.boot:spring-boot
CVE-2021-25864 Vulnerability in npm package node-red-contrib-huemagic