Vulnerabilities (CVE)

Filtered by vendor Alfresco Subscribe
Filtered by product Alfresco Content Services
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-41790 1 Alfresco 1 Alfresco Content Services 2022-07-12 6.5 MEDIUM 8.8 HIGH
An issue was discovered in Hyland org.alfresco:alfresco-content-services through 7.0.1.2. Script Action execution allows executing scripts uploaded outside of the Data Dictionary. This could allow a logged-in attacker to execute arbitrary code inside a sandboxed environment.