OpenCMS versions 7.5.3 and below suffer from cross site scripting vulnerabilities.
4e75fdecc723a1733d9e6ad8aa18826e0fa6f400e236f263c8da2b39e8e6918f
This is a proof of concept to demonstrate a logic security flow in the way Drupal CAPTCHA is used to protect login forms from bruteforce. If the CAPTCHA challenge is solved, the next login attempts can be issued without solving any new CAPTCHA challenge.
da7f99e45b5a53895b8bd9dac1825527757ca21c77e749a8c8a3b52db4fe457e