PT-2025-3950 · Hyland · Alfresco Community Edition+1
Erickfernandox
·
Published
2025-01-18
·
Updated
2025-01-19
·
CVE-2025-0557
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Hyland Alfresco Community Edition and Alfresco Enterprise Edition versions up to 6.2.2
Description
A problematic vulnerability has been found in the URL Handler component of Hyland Alfresco Community Edition and Alfresco Enterprise Edition. This issue affects an unknown part of the file
/share/s/ and leads to cross-site scripting. The attack can be initiated remotely. It is recommended to upgrade the affected component to address this issue.Recommendations
For versions up to 6.2.2, upgrade to version 7.0 to address this issue.
As a temporary workaround, consider restricting access to the
/share/s/ endpoint of the URL Handler component until a patch is available.Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alfresco Community Edition
Alfresco Enterprise Edition