CVE-2020-8778
MEDIUMAlfresco < 5.2.7 and < 6.2.0 - Authenticated Stored Cross-Site Scripting via Uploaded Document
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-8778. PoCs published by Alexandre ZANNI.
AI-analyzed exploit summary This is a detailed writeup describing three stored XSS vulnerabilities in Alfresco before 5.2.4. It includes payloads, steps to reproduce, and technical details for each CVE (CVE-2020-8776, CVE-2020-8777, CVE-2020-8778).
Description
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write access to a project.
Exploits (1)
This is a detailed writeup describing three stored XSS vulnerabilities in Alfresco before 5.2.4. It includes payloads, steps to reproduce, and technical details for each CVE (CVE-2020-8776, CVE-2020-8777, CVE-2020-8778).
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N