
CVE-2019-14223: Open Redirect in Alfresco Share
The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request. By manipulation the “failure” parameter an attacker can redirect a victim to a malicious website over any protocol the attacker desires (E.g. http, https, ftp, smb, etc.)
The disclosure for this vulnerability can be found here.
More details and the exploitation process can be found in this PDF.