mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-07 11:06:19 +00:00
884 B
884 B
CVE-2020-8777
Description
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, as demonstrated by a SCRIPT element in an SVG document.
POC
Reference
- http://packetstormsecurity.com/files/156599/Alfresco-5.2.4-Cross-Site-Scripting.html
- http://packetstormsecurity.com/files/156599/Alfresco-5.2.4-Cross-Site-Scripting.html