Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2019-14224 — CVE-2019-14224: Authenticated Remote Code Execution in Alfresco Community | Kitploit
Tools/GitHubGitHub/mbadanoiu/cve-2019-14224
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubmbadanoiu/cve-2019-14224

CVE-2019-14224

CVE-2019-14224: Authenticated Remote Code Execution in Alfresco Community

View Repository
1 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2019-14224: Authenticated Remote Code Execution in Alfresco Community

By leveraging multiple components in the Alfresco Software applications, an exploit chain was observed that allows an attacker to achieve remote code execution. The attacker must use Alfresco to:

  • Upload malicious Solr configuration files to a known/discoverable location
  • Create a Solr Core which will trigger a JMX connection from the victim back to the attacker
  • Host a malicious RMI server that will send a malicious Java object that results in deserialization and code execution.

NVD Disclosure:

The disclosure for this vulnerability can be found here.

Requirements:

This vulnerability requires:

  • Access and valid user credentials for the Alfresco Admin Console
  • Access to the Alfresco WebDAV or Alfresco Share
  • Access to the Alfresco Solr interface

Proof Of Concept:

More details and the exploitation process can be found in this PDF.

Additional Information:

Unauthenticated access to the Alfresco Solr interface may be obtained via CVE-2019-14222: Default Certificate in Alfresco Community

Download Tool