Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2cw4-g2qv-f48w

Опубликовано: 11 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions and achieve RCE (Remote Code Execution). NOTE: this issue exists because of an incomplete fix for CVE-2020-12873.

An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions and achieve RCE (Remote Code Execution). NOTE: this issue exists because of an incomplete fix for CVE-2020-12873.

EPSS

Процентиль: 90%
0.05683
Низкий

8.8 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 лет назад

An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions and achieve RCE (Remote Code Execution). NOTE: this issue exists because of an incomplete fix for CVE-2020-12873.

CVSS3: 8.8
fstec
около 2 лет назад

Уязвимость компонента folder.get.html.ftl системы управления содержимым Hyland Alfresco Community Edition, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 90%
0.05683
Низкий

8.8 High

CVSS3

Дефекты

CWE-74