S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-6380 Scanner

CVE-2023-6380 scanner - Open Redirect vulnerability in Open CMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-6380
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Open redirect vulnerability has been found in the Open CMS product affecting versions 14 and 15 of the 'Mercury' template. An attacker could create a specially crafted URL and send it to a specific user to redirect them to a malicious site and compromise them. Exploitation of this vulnerability is possible due to the fact that there is no proper sanitization of the 'URI' parameter.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Open CMSby Alkacon
14
Updated Sep 10, 2026View on NVD →
Detail

Open CMS is an open-source content management system designed to simplify the creation and management of websites. It is a widely used platform that allows users to easily add, modify and publish website content without requiring significant technical expertise. The system boasts a modular architecture that enhances its flexibility and scalability, giving developers the freedom to build rich and complex web applications with ease.

The detected vulnerability, CVE-2023-6380, pertains to the Mercury template used in Versions 14 and 15 of Open CMS. An attacker could use this vulnerability to trigger a redirect to a malicious website by crafting a URL with a specially designed 'URI' parameter. This requires no authentication and can easily catch an unsuspecting user off guard, leading to a potential compromise of sensitive data or the takeover of an entire system.

When exploited, the Open CMS vulnerability can enable a cybercriminal to execute phishing scams, send spam, plant malware, steal credentials and execute various other attacks. They could redirect targets to a website that looks exactly like a legitimate one, leading to the collection of valuable information like login credentials. In addition, attackers could compromise an entire network with a single simple click, leading to resource drain or complete control of the system - the potential damages are limitless.

In conclusion, being informed about digital vulnerabilities is critical in safeguarding one's digital assets from cyber threats. By leveraging the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets: detecting and mitigating risks before they cause damage. Don't fall victim to the Open CMS vulnerability - take the necessary precautions today!

 

REFERENCES

Solution Advice

Mitigating the risks associated with Open CMS vulnerability can be accomplished through the following precautions:

  • Update Open CMS versions 14 and 15 to the latest release
  • Utilize Open CMS-approved updates, patches and add-ons
  • Emphasize the importance of exercising caution when clicking on unknown links
  • Implement and regularly execute data backup and disaster recovery plans
  • Run Threat Intelligence and Malware analysis on your Open CMS contents.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-6380 scanner - Open Redirect vulnerability in Open CMS | S4E