
CVE-2019-14224: Authenticated Remote Code Execution in Alfresco Community
By leveraging multiple components in the Alfresco Software applications, an exploit chain was observed that allows an attacker to achieve remote code execution. The attacker must use Alfresco to:
The disclosure for this vulnerability can be found here.
This vulnerability requires:
More details and the exploitation process can be found in this PDF.
Unauthenticated access to the Alfresco Solr interface may be obtained via CVE-2019-14222: Default Certificate in Alfresco Community