Description: OpenCMS v10.5.4 and before is vulnerable to cross site scripting in New User module for parameter First Name and Last Name Impacted URL is http://[your_webserver_ip]/opencms/system/workplace/admin/accounts/user_new.jsp Payload used in PoC is "TestXSS