← Back to CVE List

CVE-2021-3312

Published: 2021-10-08T15:15Z
Last Modified: 2024-11-21T06:21Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt