High severity7.5NVD Advisory· Published Sep 17, 2020· Updated Jun 17, 2026
CVE-2020-25727
CVE-2020-25727
Description
The Reset Password add-on before 1.2.0 for Alfresco suffers from CMIS-SQL Injection, which allows a malicious user to inject a query within the email input field.
Affected products
3- cpe:2.3:a:flexsolution:reset_password:*:*:*:*:*:alfresco:*:*Range: <1.2.0
- Alfresco/Reset Password add-ondescription
- Range: <1.2.0
Patches
Vulnerability mechanics
References
1- amriunix.com/post/alfresco-reset-password-add-on-0-day-vulnerabilities/nvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.