9
CVSSv2

CVE-2020-12873

Published: 19/02/2021 Updated: 25/02/2021
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

An issue exists in Alfresco Enterprise Content Management (ECM) prior to 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running Alfresco.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

atlassian alfresco enterprise content management

Github Repositories

CVE-2023-49964: FreeMarker Server-Side Template Injection in Alfresco

CVE-2023-49964: FreeMarker Server-Side Template Injection in Alfresco An issue was discovered in Hyland Alfresco Community Edition <=720 By inserting malicious content in the foldergethtmlftl file, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions and achieve RCE (Remote Code