Hyland Alfresco Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Hyland Alfresco Community Edition and Alfresco Enterprise Edition versions through 6.2.2. The issue resides in the URL Handler component, specifically within the /share/s/ endpoint. This vulnerability allows remote attackers to inject malicious scripts that are executed in the context of the victim's browser, potentially compromising data integrity and confidentiality.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can execute arbitrary scripts in the context of the user's browser.

Reproduction

The vulnerability can be reproduced by injecting a script payload into an unsanitized parameter of the /share/s/ endpoint. When the crafted URL is accessed, the injected JavaScript executes in the browser of the user, demonstrating the cross-site scripting flaw.

Remediation

Users are advised to upgrade to Alfresco Community Edition or Alfresco Enterprise Edition version 7.0 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
7.7
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.