Lucene search

K
cvelistMitreCVELIST:CVE-2021-3312
HistoryOct 08, 2021 - 2:44 p.m.

CVE-2021-3312

2021-10-0814:44:58
mitre
www.cve.org
3
xml external entity file exfiltration alkacon opencms

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

47.5%

An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server’s file system by uploading a crafted SVG document.

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

47.5%

Related for CVELIST:CVE-2021-3312