Vulnerability Description
An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alkacon | Opencms | 11.0 |
Related Weaknesses (CWE)
References
- https://github.com/alkacon/opencms-core/issues/725ExploitIssue TrackingThird Party Advisory
- https://github.com/alkacon/opencms-core/releasesRelease NotesThird Party Advisory
- https://github.com/alkacon/opencms-core/issues/725ExploitIssue TrackingThird Party Advisory
- https://github.com/alkacon/opencms-core/releasesRelease NotesThird Party Advisory
FAQ
What is CVE-2021-3312?
CVE-2021-3312 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by upload...
How severe is CVE-2021-3312?
CVE-2021-3312 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3312?
Check the references section above for vendor advisories and patch information. Affected products include: Alkacon Opencms.