漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions and achieve RCE (Remote Code Execution). NOTE: this issue exists because of an incomplete fix for CVE-2020-12873.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Alfresco Community Edition 安全漏洞
Vulnerability Description
Alfresco Community Edition是美国Alfresco公司的一套开源的企业内容管理系统的社区版。该系统包括文档管理、办公协作等功能。 Alfresco Community Edition 7.2.0 及之前版本存在安全漏洞,该漏洞源于可以通过folder.get.html.ftl文件插入恶意内容,攻击者利用该漏洞可能会执行服务器端模板注入。
CVSS Information
N/A
Vulnerability Type
N/A