CVE-2014-9302 describes a Server-Side Request Forgery (SSRF) vulnerability within the cmisbrowser servlet of Alfresco Community Edition 5.0.a and earlier. This flaw allows unauthenticated remote attackers to trigger outbound requests from the server by manipulating the 'url' parameter in a crafted URI. While the CVSS score is 5.0 (Medium) with no confidentiality or availability impact, exploit code exists on ExploitDB, indicating a known method for exploitation. Despite this, there is no evidence of active exploitation, and community discussion or media coverage is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.0.aCPE matchmatch criteria | cpe:2.3:a:alfresco:community_edition:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.