PT-2021-9474 · Alfresco · Alfresco Enterprise Content Management
Alvaro Munoz
+1
·
Published
2021-02-19
·
Updated
2023-12-14
·
CVE-2020-12873
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Alfresco Enterprise Content Management (ECM) versions prior to 6.2.1
Description
An issue was discovered that allows a user with privileges to edit a FreeMarker template to execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running Alfresco.
Recommendations
For versions prior to 6.2.1, update to version 6.2.1 or later to resolve the issue.
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alfresco Enterprise Content Management