{ "id": "CVE-2024-41447", "sourceIdentifier": "cve@mitre.org", "published": "2025-04-18T17:15:33.183", "lastModified": "2025-04-18T17:15:33.183", "vulnStatus": "Received", "cveTags": [], "descriptions": [ { "lang": "en", "value": "A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the author parameter under the Create/Modify article function." } ], "metrics": {}, "references": [ { "url": "https://www.exploit-db.com/exploits/52209", "source": "cve@mitre.org" } ] }