Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-41079

Опубликовано: 04 дек. 2025
Источник: redhat
CVSS3: 6.1

Описание

A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by storing malicious payloads with PUT parámetro 'name' in '/api/v2.1/user/'.

A flaw was found in Seafile. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by storing malicious payloads with PUT parameter 'name' in '/api/v2.1/user/'.

Отчет

This vulnerability is rated Moderate for Red Hat as it is a stored Cross-Site Scripting (XSS) flaw in Seafile that allows an attacker to execute arbitrary code in a victim's browser. This affects Seafile in Fedora 42 and Fedora 43, which are community projects.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2418783Seafile: Seafile: Stored Cross-Site Scripting (XSS) vulnerability

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
4 месяца назад

A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by storing malicious payloads with PUT parámetro 'name' in '/api/v2.1/user/'.

CVSS3: 6.1
debian
4 месяца назад

A stored Cross-Site Scripting (XSS) vulnerability has been found in Se ...

CVSS3: 6.1
github
4 месяца назад

A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by storing malicious payloads with PUT parámetro 'name' in '/api/v2.1/user/'.

6.1 Medium

CVSS3