Vulnerabilities
Vulnerable Software
Alfresco:  >> Alfresco  >> 6.1  Security Vulnerabilities
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a file.
CVSS Score
5.4
EPSS Score
0.008
Published
2020-03-02
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, as demonstrated by a SCRIPT element in an SVG document.
CVSS Score
5.4
EPSS Score
0.006
Published
2020-03-02
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write access to a project.
CVSS Score
5.4
EPSS Score
0.008
Published
2020-03-02
An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request. By manipulating the POST parameters, an attacker can redirect a victim to a malicious website over any protocol the attacker desires (e.g.,http, https, ftp, smb, etc.).
CVSS Score
6.1
EPSS Score
0.593
Published
2019-09-06


Contact Us

Shodan ® - All rights reserved