Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 Maven

XML External Entity Reference in org.opencms:opencms-core

GHSA-g6v7-vqhx-6v6c · CVE-2021-3312

Published · Modified

Description

An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document.

Ready to move

Start Securing

Free, no credit card | First findings in minutes