CVE-2021-3312

CVSS v3.1 6.5 (Medium)
65% Progress
CVSS v2.0 4 (Medium)
40% Progress
EPSS 0.13 % (48th)
0.13% Progress
Affected Products 1
Advisories 1

An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document.

Weaknesses
CWE-611
Improper Restriction of XML External Entity Reference
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2021-10-08 15:15:09
(2 years ago)
Updated Date
2021-10-15 13:42:35
(2 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Alkacon Opencms 11.0 cpe:2.3:a:alkacon:opencms:11.0:-
  Alkacon Opencms 11.0.1 cpe:2.3:a:alkacon:opencms:11.0.1
  Alkacon Opencms 11.0.2 cpe:2.3:a:alkacon:opencms:11.0.2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...