6.8
CVSSv2

CVE-2014-9300

Published: 07/12/2014 Updated: 17/02/2015
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition prior to 5.0.a allows remote malicious users to hijack the authentication of users for requests that access unauthorized URLs and obtain user credentials via a URL in the url parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

alfresco alfresco