Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Alkacon OpenCms 代码问题漏洞
Vulnerability Description
Alkacon OpenCms是一套使用Java语言开发的开源内容管理系统(CMS)。 Alkacon OpenCms 11.0, 11.0.1 和 11.0.2版本存在代码问题漏洞,该漏洞源于软件缺乏对于XML外部实体的有效限制,漏洞允许具有编辑权限的远程认证用户通过上传精心制作的SVG文档从服务器的文件系统中过滤文件。
CVSS Information
N/A
Vulnerability Type
N/A