CVE-2019-14223: Alfresco

Medium severity, CVSS 6.1. EPSS: 4.5% chance of exploitation in the next 30 days.

An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request. By manipulating the POST parameters, an attacker can redirect a victim to a malicious website over any protocol the attacker desires (e.g.,http, https, ftp, smb, etc.).

Affected products

  • Alfresco Alfresco: before 5.2.6 (fixed in 5.2.6); version 6.0 only; version 6.1 only

Published 2019-09-06. Last modified 2026-06-17.