Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-37j8-qv27-g3fq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running Alfresco.

An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running Alfresco.

EPSS

Процентиль: 80%
0.01446
Низкий

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 8.8
nvd
почти 5 лет назад

An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running Alfresco.

EPSS

Процентиль: 80%
0.01446
Низкий

Дефекты

CWE-74