Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Admin account takeover in Alfresco Reset Password
Vulnerability Description
The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can get admin's access to the system using the vulnerability in the project. Impacts all servers where this add-on is installed. The problem is fixed in version 1.2.0
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Vulnerability Type
输入验证不恰当
Vulnerability Title
Alfresco 安全漏洞
Vulnerability Description
Alfresco是一款开源的企业内容管理系统。该平台页面采用Freemarker开发,主要功能包括文档管理、协作、记录管理、知识库管理、Web内容管理等。 Alfresco 1.2.0版本之前存在安全漏洞。该漏洞源于重设密码插件依赖于不可信的输入来进行安全决策。攻击者可利用该的漏洞获得管理员对系统的访问权。
CVSS Information
N/A
Vulnerability Type
N/A