8.8
CVSSv3

CVE-2023-49964

Published: 11/12/2023 Updated: 14/12/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An issue exists in Hyland Alfresco Community Edition up to and including 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions and achieve RCE (Remote Code Execution). NOTE: this issue exists because of an incomplete fix for CVE-2020-12873.

Vulnerable Product Search on Vulmon Subscribe to Product

hyland alfresco content services

Github Repositories

CVE-2023-49964: FreeMarker Server-Side Template Injection in Alfresco

CVE-2023-49964: FreeMarker Server-Side Template Injection in Alfresco An issue was discovered in Hyland Alfresco Community Edition <=720 By inserting malicious content in the foldergethtmlftl file, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions and achieve RCE (Remote Code