Show filters
19 Total Results
Displaying 1-10 of 19
Sort by:
Attacker Value
Low

CVE-2014-9301

Disclosure Date: December 07, 2014 (last updated October 05, 2023)
Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows remote attackers to trigger outbound requests to intranet servers, conduct port scans, and read arbitrary files via a crafted URI in the endpoint parameter.
0
Attacker Value
Unknown

CVE-2025-0557

Disclosure Date: January 18, 2025 (last updated January 18, 2025)
A vulnerability classified as problematic has been found in Hyland Alfresco Community Edition and Alfresco Enterprise Edition up to 6.2.2. This affects an unknown part of the file /share/s/ of the component URL Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.0 is able to address this issue. It is recommended to upgrade the affected component.
Attacker Value
Unknown

CVE-2024-40347

Disclosure Date: July 20, 2024 (last updated August 23, 2024)
A reflected cross-site scripting (XSS) vulnerability in Hyland Alfresco Platform 23.2.1-r96 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the parameter htmlid.
Attacker Value
Unknown

CVE-2023-49964

Disclosure Date: December 11, 2023 (last updated December 15, 2023)
An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions and achieve RCE (Remote Code Execution). NOTE: this issue exists because of an incomplete fix for CVE-2020-12873.
Attacker Value
Unknown

CVE-2020-18327

Disclosure Date: March 04, 2022 (last updated October 07, 2023)
Cross Site Scripting (XSS) vulnerability exists in Alfresco Alfresco Community Edition v5.2.0 via the action parameter in the alfresco/s/admin/admin-nodebrowser API. Fixed in v6.2
Attacker Value
Unknown

CVE-2021-41792

Disclosure Date: October 21, 2021 (last updated February 23, 2025)
An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-transform-services through 1.3. A crafted HTML file, once uploaded, could trigger an unexpected request by the transformation engine. The response to the request is not available to the attacker, i.e., this is blind SSRF.
Attacker Value
Unknown

CVE-2021-41790

Disclosure Date: October 21, 2021 (last updated February 23, 2025)
An issue was discovered in Hyland org.alfresco:alfresco-content-services through 7.0.1.2. Script Action execution allows executing scripts uploaded outside of the Data Dictionary. This could allow a logged-in attacker to execute arbitrary code inside a sandboxed environment.
Attacker Value
Unknown

CVE-2020-12873

Disclosure Date: February 19, 2021 (last updated February 22, 2025)
An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running Alfresco.
Attacker Value
Unknown

CVE-2020-8777

Disclosure Date: March 02, 2020 (last updated February 21, 2025)
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, as demonstrated by a SCRIPT element in an SVG document.
Attacker Value
Unknown

CVE-2020-8776

Disclosure Date: March 02, 2020 (last updated February 21, 2025)
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a file.