Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-49964

Опубликовано: 11 дек. 2023
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions and achieve RCE (Remote Code Execution). NOTE: this issue exists because of an incomplete fix for CVE-2020-12873.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hyland:alfresco_content_services:*:*:*:*:community:*:*:*
Версия до 7.2.0 (включая)

EPSS

Процентиль: 90%
0.05683
Низкий

8.8 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 8.8
github
около 2 лет назад

An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions and achieve RCE (Remote Code Execution). NOTE: this issue exists because of an incomplete fix for CVE-2020-12873.

CVSS3: 8.8
fstec
около 2 лет назад

Уязвимость компонента folder.get.html.ftl системы управления содержимым Hyland Alfresco Community Edition, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 90%
0.05683
Низкий

8.8 High

CVSS3

Дефекты

CWE-74