Description


An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-transform-services through 1.3. A crafted HTML file, once uploaded, could trigger an unexpected request by the transformation engine. The response to the request is not available to the attacker, i.e., this is blind SSRF.

Related CPE's


a

alfresco

alfresco_content_services

4

Weaknesses



CWE-918

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

5.3 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-10-21T07:15:08.913Z

4 years ago

Last modified

2024-11-21T05:26:46.370Z

1 year ago