CVE-2023-49964 Information
Dec 14, 2023
cve
Description
An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file an attacker may perform SSTI (Server-Side Template Injection) attacks which can leverage FreeMarker exposed objects to bypass restrictions and achieve RCE (Remote Code Execution). NOTE: this issue exists because of an incomplete fix for CVE-2020-12873.
Reference
https://www.alfresco.com/products/community/download https://github.com/mbadanoiu/CVE-2023-49964
Share on: