Description
An arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.
Remediation
References
https://www.exploit-db.com/exploits/51564
Related Vulnerabilities
CVE-2022-34662 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-common
CVE-2017-16190 Vulnerability in npm package dcdcdcdcdc
CVE-2022-36094 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2023-49381 Vulnerability in maven package com.jfinal:jfinal