Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-83570
HistoryOct 25, 2021 - 12:00 a.m.

Alfresco Cross-Site Scripting Vulnerability (CNVD-2021-83570)

2021-10-2500:00:00
China National Vulnerability Database
www.cnvd.org.cn
5
alfresco
cross-site scripting
vulnerability
freemarker
document management
collaboration
records management
validation
web application
client-side code

EPSS

0.001

Percentile

19.4%

Alfresco is an open source enterprise content management system. The platform pages are developed using Freemarker and the main features include document management, collaboration, records management, knowledge base management, Web content management, etc. A security vulnerability exists in Alfresco, which stems from the lack of proper validation of client-side data by the WEB application. An attacker could exploit the vulnerability to execute client-side code.

EPSS

0.001

Percentile

19.4%

Related for CNVD-2021-83570