Vulnerability Details CVE-2019-14223
An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request. By manipulating the POST parameters, an attacker can redirect a victim to a malicious website over any protocol the attacker desires (e.g.,http, https, ftp, smb, etc.).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.593
EPSS Ranking 98.1%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 5.8
Products affected by CVE-2019-14223
-
cpe:2.3:a:alfresco:alfresco:4.2.f
-
cpe:2.3:a:alfresco:alfresco:5.0.a
-
cpe:2.3:a:alfresco:alfresco:5.2
-
cpe:2.3:a:alfresco:alfresco:6.0
-
cpe:2.3:a:alfresco:alfresco:6.1