VulnerabilityModified
CVE-2019-14223
The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request.
MEDIUM 6.1EPSS 4.47%
Does this matter?
Lower severity and a low EPSS score (4.47%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request. By manipulating the POST parameters, an attacker can redirect a victim to a malicious website over any protocol the attacker desires (e.g.,http, https, ftp, smb, etc.).
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 4.47% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- alfresco/alfresco
- Source
- cve@mitre.org
References
- https://community.alfresco.com/content?filterID=all~objecttype~thread%5Bquestions%5DVendor Advisory
- https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-14223-Open%20Redirect%20in%20Alfresco%20Share-Alfresco%20CommunityExploit, Third Party Advisory
- https://community.alfresco.com/content?filterID=all~objecttype~thread%5Bquestions%5DVendor Advisory
- https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-14223-Open%20Redirect%20in%20Alfresco%20Share-Alfresco%20CommunityExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.