SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-14223

The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request.

MEDIUM 6.1EPSS 4.47%

Does this matter?

Lower severity and a low EPSS score (4.47%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request. By manipulating the POST parameters, an attacker can redirect a victim to a malicious website over any protocol the attacker desires (e.g.,http, https, ftp, smb, etc.).

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
4.47% probability · 91th percentile
CISA KEV
Not listed
Weakness
CWE-601
Affected
alfresco/alfresco
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.