PT-2025-3950 · Hyland · Alfresco Community Edition+1

Erickfernandox

·

Published

2025-01-18

·

Updated

2025-01-19

·

CVE-2025-0557

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Hyland Alfresco Community Edition and Alfresco Enterprise Edition versions up to 6.2.2
Description A problematic vulnerability has been found in the URL Handler component of Hyland Alfresco Community Edition and Alfresco Enterprise Edition. This issue affects an unknown part of the file /share/s/ and leads to cross-site scripting. The attack can be initiated remotely. It is recommended to upgrade the affected component to address this issue.
Recommendations For versions up to 6.2.2, upgrade to version 7.0 to address this issue. As a temporary workaround, consider restricting access to the /share/s/ endpoint of the URL Handler component until a patch is available.

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-0557

Affected Products

Alfresco Community Edition
Alfresco Enterprise Edition