PT-2019-15858 · Alfresco · Alfresco Enterprise

Vipinxsec

·

Published

2019-12-02

·

Updated

2024-03-05

·

CVE-2019-19496

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Alfresco Enterprise versions prior to 5.2.5
Description The issue allows for stored XSS via an uploaded HTML document. This means an attacker can upload a malicious HTML file to the system, which can then execute scripts on the user's browser, potentially leading to unauthorized actions or data theft.
Recommendations For versions prior to 5.2.5, update to version 5.2.5 or later to resolve the issue. As a temporary workaround, consider restricting the upload of HTML documents to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-19496

Affected Products

Alfresco Enterprise