CVE-2022-28051
- EPSS 0.62%
- Veröffentlicht 06.06.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:56:40
The "Add category" functionality inside the "Global Keywords" menu in "SeedDMS" version 6.0.18 and 5.1.25, is prone to stored XSS which allows an attacker to inject malicious javascript code.
CVE-2021-45408
- EPSS 0.21%
- Veröffentlicht 04.02.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:32:10
Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect users to malicious sites using the "referuri" parameter.
CVE-2020-23048
- EPSS 0.33%
- Veröffentlicht 22.10.2021 20:15:10
- Zuletzt bearbeitet 21.11.2024 05:13:32
SeedDMS Content Management System v6.0.7 contains a persistent cross-site scripting (XSS) vulnerability in the component AddEvent.php via the name and comment parameters.
CVE-2021-36543
- EPSS 0.11%
- Veröffentlicht 03.08.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:13:48
Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.UnlockDocument.php in SeedDMS v5.1.x <5.1.23 and v6.0.x <6.0.16 allows a remote attacker to unlock any document without victim's knowledge, by enticing an authenticated user to visit an at...
CVE-2021-36542
- EPSS 0.1%
- Veröffentlicht 03.08.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:13:48
Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.LockDocument.php in SeedDMS v5.1.x<5.1.23 and v6.0.x <6.0.16 allows a remote attacker to lock any document without victim's knowledge, by enticing an authenticated user to visit an attacke...
CVE-2021-35343
- EPSS 0.1%
- Veröffentlicht 03.08.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:12:14
Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.Ajax.php in SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 allows a remote attacker to edit document name without victim's knowledge, by enticing an authenticated user to visit an attacker's web ...
CVE-2021-26216
- EPSS 0.16%
- Veröffentlicht 18.03.2021 16:15:14
- Zuletzt bearbeitet 21.11.2024 05:55:55
SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php.
CVE-2021-26215
- EPSS 0.16%
- Veröffentlicht 18.03.2021 16:15:14
- Zuletzt bearbeitet 21.11.2024 05:55:55
SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditDocument.php.
CVE-2020-28727
- EPSS 0.45%
- Veröffentlicht 07.12.2020 08:15:10
- Zuletzt bearbeitet 21.11.2024 05:23:09
Cross-site scripting (XSS) exists in SeedDMS 6.0.13 via the folderid parameter to views/bootstrap/class.DropFolderChooser.php.
CVE-2020-28726
- EPSS 0.2%
- Veröffentlicht 24.11.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:23:09
Open redirect in SeedDMS 6.0.13 via the dropfolderfileform1 parameter to out/out.AddDocument.php.