Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-30587

Опубликовано: 25 мар. 2026
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

Multiple Stored XSS vulnerabilities exist in Seafile Server version 13.0.15,13.0.16-pro,12.0.14 and prior and fixed in 13.0.17, 13.0.17-pro, and 12.0.20-pro, via the Seadoc (sdoc) editor. The application fails to properly sanitize WebSocket messages regarding document structure updates. This allows authenticated remote attackers to inject malicious JavaScript payloads via the src attribute of embedded Excalidraw whiteboards or the href attribute of anchor tags

A flaw was found in Seafile Server and its Seadoc editor. This Stored Cross-Site Scripting (XSS) vulnerability allows authenticated remote attackers to inject malicious JavaScript code. The application fails to properly sanitize WebSocket messages during document structure updates. By exploiting this, an attacker can execute arbitrary client-side scripts, potentially leading to information disclosure or unauthorized actions within a user's browser.

Отчет

This MODERATE stored XSS vulnerability in Seafile Server's Seadoc editor allows authenticated users to inject malicious scripts via unsanitized WebSocket messages. Exploitation requires low privileges (any authenticated user) and user interaction (victim views document). Impact is high to confidentiality and integrity. Affects Seafile Server 13.0.15, 13.0.16-pro, 12.0.14 and prior. Fixed in 13.0.17, 13.0.17-pro, and 12.0.20-pro.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2451404Seafile Server: Seadoc editor: seahub: seadoc-editor: Seafile Server: Arbitrary client-side code execution via Stored Cross-Site Scripting in Seadoc editor

EPSS

Процентиль: 20%
0.00278
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.7
nvd
5 месяцев назад

Multiple Stored XSS vulnerabilities exist in Seafile Server version 13.0.15,13.0.16-pro,12.0.14 and prior and fixed in 13.0.17, 13.0.17-pro, and 12.0.20-pro, via the Seadoc (sdoc) editor. The application fails to properly sanitize WebSocket messages regarding document structure updates. This allows authenticated remote attackers to inject malicious JavaScript payloads via the src attribute of embedded Excalidraw whiteboards or the href attribute of anchor tags

CVSS3: 8.7
debian
5 месяцев назад

Multiple Stored XSS vulnerabilities exist in Seafile Server version 13 ...

CVSS3: 5.4
github
5 месяцев назад

Seafile Server has multiple stored XSS vulnerabilities

EPSS

Процентиль: 20%
0.00278
Низкий

6.3 Medium

CVSS3