{"id":"CVE-2019-13237","aliases":["GHSA-36hf-6hp2-9g4c"],"url":"https://o3.security/vulnerability/CVE-2019-13237","summary":"Local file inclusion allows unauthorized access to internal resources in Alkacon OpenCms","details":"In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and /system/workplace/admin/history/settings/index.jsp.","published":"2019-08-27T12:15:12.593Z","modified":"2026-07-08T05:54:51.841173085Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Maven","name":"org.opencms:opencms-core","fixedVersion":"11.0.1"}],"fix":null,"references":[{"type":"FIX","url":"https://github.com/alkacon/opencms-core/commits/branch_10_5_x"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/154281/Alkacon-OpenCMS-10.5.x-Local-File-Inclusion.html"},{"type":"EVIDENCE","url":"https://aetsu.github.io/OpenCms"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:54:51.841173085Z"}}