Описание
SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable to stored XSS. An attacker with admin privileges can inject the payload inside the "Role management" menu and then trigger the payload by loading the "Users management" menu
Ссылки
- ExploitPatchThird Party Advisory
- PatchVendor Advisory
- ExploitPatchThird Party Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:seeddms:seeddms:5.1.25:*:*:*:*:*:*:*
cpe:2.3:a:seeddms:seeddms:6.0.18:*:*:*:*:*:*:*
EPSS
Процентиль: 68%
0.00558
Низкий
4.8 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 4.8
github
больше 3 лет назад
SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable to stored XSS. An attacker with admin privileges can inject the payload inside the "Role management" menu and then trigger the payload by loading the "Users management" menu
EPSS
Процентиль: 68%
0.00558
Низкий
4.8 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79