CVE-2019-14223
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request. By manipulating the POST parameters, an attacker can redirect a victim to a malicious website over any protocol the attacker desires (e.g.,http, https, ftp, smb, etc.).
Se descubrió un problema en Alfresco Community Edition versiones inferiores a 5.2.6, 6.0.N y 6.1.N. La aplicación Alfresco Share es vulnerable a un ataque de Redireccionamiento Abierto por medio de una petición POST especialmente diseñada. Mediante la manipulación de los parámetros POST, un atacante puede redireccionar a una víctima a un sitio web malicioso por medio de cualquier protocolo que el atacante desee (p.ej., http, https, ftp, smb, etc.).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-07-21 CVE Reserved
- 2019-09-06 CVE Published
- 2024-03-04 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-14223-Open%20Redirect%20in%20Alfresco%20Share-Alfresco%20Community | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://community.alfresco.com/content?filterID=all~objecttype~thread%5Bquestions%5D | 2020-07-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Alfresco Search vendor "Alfresco" | Alfresco Search vendor "Alfresco" for product "Alfresco" | < 5.2.6 Search vendor "Alfresco" for product "Alfresco" and version " < 5.2.6" | community |
Affected
| ||||||
Alfresco Search vendor "Alfresco" | Alfresco Search vendor "Alfresco" for product "Alfresco" | 6.0 Search vendor "Alfresco" for product "Alfresco" and version "6.0" | community |
Affected
| ||||||
Alfresco Search vendor "Alfresco" | Alfresco Search vendor "Alfresco" for product "Alfresco" | 6.1 Search vendor "Alfresco" for product "Alfresco" and version "6.1" | community |
Affected
|