Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-103408
HistoryOct 11, 2021 - 12:00 a.m.

Alkacon OpenCms XML External Entity Vulnerability

2021-10-1100:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
alkacon opencms
vulnerability
xml
file theft
exploit
svg

EPSS

0.001

Percentile

47.5%

Alkacon OpenCms is an open source content management system (CMS) developed in Java.Alkacon OpenCms is vulnerable to an XML external entity vulnerability that can be exploited by attackers to steal files from the server’s file system by uploading crafted SVG documents.

EPSS

0.001

Percentile

47.5%

Related for CNVD-2021-103408