PT-2021-20053 · Alkacon · Alkacon Opencms

Gwestenberger

·

Published

2021-10-08

·

Updated

2021-10-15

·

CVE-2021-3312

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Alkacon OpenCms versions 11.0 through 11.0.2
Description An XML external entity (XXE) issue allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document.
Recommendations For versions 11.0 through 11.0.2, update to a version that includes a fix for this issue to prevent file exfiltration. As a temporary workaround, consider restricting the upload of SVG documents or limiting edit privileges to trusted users until a patch is available.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3312
GHSA-G6V7-VQHX-6V6C

Affected Products

Alkacon Opencms