PT-2021-20053 · Alkacon · Alkacon Opencms
Gwestenberger
·
Published
2021-10-08
·
Updated
2021-10-15
·
CVE-2021-3312
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Alkacon OpenCms versions 11.0 through 11.0.2
Description
An XML external entity (XXE) issue allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document.
Recommendations
For versions 11.0 through 11.0.2, update to a version that includes a fix for this issue to prevent file exfiltration.
As a temporary workaround, consider restricting the upload of SVG documents or limiting edit privileges to trusted users until a patch is available.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alkacon Opencms