{"id":"CVE-2019-13235","aliases":["GHSA-2p6p-v69p-9mm9"],"url":"https://o3.security/vulnerability/CVE-2019-13235","summary":"XSS in login form","details":"In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.","published":"2019-08-27T12:15:12.453Z","modified":"2026-07-08T05:55:30.105946696Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Maven","name":"org.opencms:opencms-core","fixedVersion":"11.0.1"}],"fix":null,"references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/154298/Alkacon-OpenCMS-10.5.x-Cross-Site-Scripting.html"},{"type":"FIX","url":"https://github.com/alkacon/apollo-template/commits/branch_10_5_x"},{"type":"EVIDENCE","url":"https://aetsu.github.io/OpenCms"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:55:30.105946696Z"}}