CVE-2020-8778: XSS
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write access to a project.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Alfresco exploit?
The vulnerability ID for this Alfresco exploit is CVE-2020-8778.
What is the severity level of CVE-2020-8778?
The severity level of CVE-2020-8778 is medium (5.4).
What software versions are affected by CVE-2020-8778?
Alfresco Enterprise versions up to exclusive 5.2.7 and Alfresco Community versions up to exclusive 6.2.0 are affected by CVE-2020-8778.
How does the vulnerability CVE-2020-8778 manifest?
The vulnerability CVE-2020-8778 manifests as a cross-site scripting (XSS) attack via an uploaded document when the attacker has write access to a project in Alfresco Enterprise and Alfresco Community.
Are there any reference links related to CVE-2020-8778?
Yes, here are some reference links related to CVE-2020-8778: [Packet Storm Security](http://packetstormsecurity.com/files/156599/Alfresco-5.2.4-Cross-Site-Scripting.html), [GitLab Snippets](https://gitlab.com/snippets/1937042), [Alfresco Issues](https://issues.alfresco.com/jira/browse/ALF-22110).