Lucene search

K
osvGoogleOSV:GHSA-G6V7-VQHX-6V6C
HistoryOct 12, 2021 - 5:23 p.m.

XML External Entity Reference in org.opencms:opencms-core

2021-10-1217:23:40
Google
osv.dev
15
xml external entity
xxe
opencms-core
alkacon opencms
remote authenticated users
edit privileges
exfiltrate files
crafted svg document
security vulnerability
file system

EPSS

0.001

Percentile

47.5%

An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server’s file system by uploading a crafted SVG document.

EPSS

0.001

Percentile

47.5%

Related for OSV:GHSA-G6V7-VQHX-6V6C