High severity8.8NVD Advisory· Published Oct 21, 2021· Updated Jun 17, 2026
CVE-2021-41790
CVE-2021-41790
Description
An issue was discovered in Hyland org.alfresco:alfresco-content-services through 7.0.1.2. Script Action execution allows executing scripts uploaded outside of the Data Dictionary. This could allow a logged-in attacker to execute arbitrary code inside a sandboxed environment.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:alfresco:alfresco_content_services:*:*:*:*:enterprise:*:*:*+ 4 more
- cpe:2.3:a:alfresco:alfresco_content_services:*:*:*:*:enterprise:*:*:*range: >=5.0.0.0,<=5.2.7.11
- cpe:2.3:a:alfresco:alfresco_content_services:7.0.0.1:*:*:*:enterprise:*:*:*
- cpe:2.3:a:alfresco:alfresco_content_services:7.0.0.2:*:*:*:enterprise:*:*:*
- cpe:2.3:a:alfresco:alfresco_content_services:7.0:*:*:*:enterprise:*:*:*
- (no CPE)range: <=7.0.1.2
(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=7.0.1.2
Patches
Vulnerability mechanics
References
2- github.com/Alfresco/acs-packaging/blob/master/DISCLOSURES.mdnvdThird Party Advisory
- www.themissinglink.com.aunvdThird Party Advisory
News mentions
0No linked articles in our index yet.