CVE-2014-9301 EXPLOIT
6.4
MEDIUM · CVSS 2.0 · EPSS 3.9% (pctl 90)
Patch early
A public exploit exists.
Description
Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows remote attackers to trigger outbound requests to intranet servers, conduct port scans, and read arbitrary files via a crafted URI in the endpoint parameter.
Scoring
| CVSS | 6.4 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
| EPSS | 3.93% — more likely to be exploited than 90% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-12-07 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| alfresco | alfresco |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Alfresco - '/proxy?endpoint' Server-Side Request Forgery | 2014-07-16 |
References
- http://seclists.org/bugtraq/2014/Jul/72
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20140716-0_Alfresco_Community_Edition_Multiple_SSRF_vulnerabilities_v10.txt
- http://seclists.org/bugtraq/2014/Jul/72
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20140716-0_Alfresco_Community_Edition_Multiple_SSRF_vulnerabilities_v10.txt
→ the Explorer · watch your stack · NVD