Stefano Lanaro

3 exploits Active since Oct 2021
CVE-2021-41790 WRITEUP HIGH WRITEUP
Hyland org.alfresco:alfresco-content-services <7.0.1.2 - RCE
An issue was discovered in Hyland org.alfresco:alfresco-content-services through 7.0.1.2. Script Action execution allows executing scripts uploaded outside of the Data Dictionary. This could allow a logged-in attacker to execute arbitrary code inside a sandboxed environment.
CVSS 8.8
CVE-2021-41791 WRITEUP MEDIUM WRITEUP
Alfresco Community Share < 7.0 - XSS
An issue was discovered in Hyland org.alfresco:share through 7.0.0.2 and org.alfresco:community-share through 7.0. An evasion of the XSS filter for HTML input validation in the Alfresco Share User Interface leads to stored XSS that could be exploited by an attacker (given that he has privileges on the content collaboration features).
CVSS 5.4
CVE-2021-41792 WRITEUP MEDIUM WRITEUP
Alfresco Content Services < 5.2.7.11 - SSRF
An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-transform-services through 1.3. A crafted HTML file, once uploaded, could trigger an unexpected request by the transformation engine. The response to the request is not available to the attacker, i.e., this is blind SSRF.
CVSS 5.3