4
CVSSv2

CVE-2021-3312

Published: 08/10/2021 Updated: 15/10/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

alkacon opencms 11.0

alkacon opencms 11.0.1

alkacon opencms 11.0.2