CVE-2021-41791
Summary
| CVE | CVE-2021-41791 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-21 09:15:00 UTC |
| Updated | 2021-10-27 20:01:00 UTC |
| Description | An issue was discovered in Hyland org.alfresco:share through 7.0.0.2 and org.alfresco:community-share through 7.0. An evasion of the XSS filter for HTML input validation in the Alfresco Share User Interface leads to stored XSS that could be exploited by an attacker (given that he has privileges on the content collaboration features). |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Alfresco | Community Share | All | All | All | All |
| Application | Alfresco | Share | 7.0 | All | All | All |
| Application | Alfresco | Share | 7.0.0.1 | All | All | All |
| Application | Alfresco | Share | 7.0.0.2 | All | All | All |
| Application | Alfresco | Share | 7.0.1 | All | All | All |
| Application | Alfresco | Share | All | All | All | All |
| Application | Alfresco | Share | All | All | All | All |
| Application | Alfresco | Share | All | All | All | All |
| Application | Alfresco | Share | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| acs-packaging/DISCLOSURES.md at master · Alfresco/acs-packaging · GitHub | MISC | github.com | |
| Home Page | The Missing Link | MISC | www.themissinglink.com.au | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.