Medium severity5.4NVD Advisory· Published Mar 2, 2020· Updated Jun 17, 2026
CVE-2020-8777
CVE-2020-8777
Description
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, as demonstrated by a SCRIPT element in an SVG document.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- Alfresco/Alfresco Enterprisedescription
- Range: <6.2.0 (rb65251d6-b368)
- Range: <5.2.7
Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/156599/Alfresco-5.2.4-Cross-Site-Scripting.htmlnvdThird Party AdvisoryVDB Entry
- issues.alfresco.com/jira/browse/ALF-22110nvdPermissions RequiredVendor Advisory
News mentions
0No linked articles in our index yet.