{"id":"CVE-2021-3312","aliases":["GHSA-g6v7-vqhx-6v6c"],"url":"https://o3.security/vulnerability/CVE-2021-3312","summary":"XML External Entity Reference in org.opencms:opencms-core","details":"An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document.","published":"2021-10-08T15:15:09.217Z","modified":"2026-08-07T17:02:11.014191Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"org.opencms:opencms-core","fixedVersion":"12.0.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/alkacon/opencms-core/releases"},{"type":"REPORT","url":"https://github.com/alkacon/opencms-core/issues/725"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T17:02:11.014191Z"}}