An issue was discovered in Hyland org.alfresco:alfresco-content-services through 7.0.1.2. Script Action execution allows executing scripts uploaded outside of the Data Dictionary. This could allow a logged-in attacker to execute arbitrary code inside a sandboxed environment.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Alfresco_content_services | Alfresco | 5.0.0.0 (including) | 5.2.7.11 (including) |
Alfresco_content_services | Alfresco | 6.0.0.0 (including) | 6.0.1.9 (including) |
Alfresco_content_services | Alfresco | 6.1.0.0 (including) | 6.1.1.10 (including) |
Alfresco_content_services | Alfresco | 6.2.0.0 (including) | 6.2.2.18 (including) |
Alfresco_content_services | Alfresco | 7.0.1.0 (including) | 7.0.1.2 (including) |
Alfresco_content_services | Alfresco | 7.0 (including) | 7.0 (including) |
Alfresco_content_services | Alfresco | 7.0.0.1 (including) | 7.0.0.1 (including) |
Alfresco_content_services | Alfresco | 7.0.0.2 (including) | 7.0.0.2 (including) |