CVE-2020-15181

CRITICAL

Alfresco Reset Password <1.2.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can get admin's access to the system using the vulnerability in the project. Impacts all servers where this add-on is installed. The problem is fixed in version 1.2.0

Scores

CVSS v3 9.3
EPSS 0.0142
EPSS Percentile 69.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Details

CWE
CWE-20 CWE-284
Status published
Products (1)
alfresco/reset_password < 1.2.0
Published Sep 18, 2020
Tracked Since Feb 18, 2026