PT-2019-12951 · Seeddms · Seeddms

Publicado

2019-06-17

·

Atualizado

2019-06-24

·

CVE-2019-12801

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SeedDMS version 5.1.11
Description The issue allows for Stored XSS by creating a new group with a JavaScript payload as the GROUP Name in the out/out.GroupMgr.php file.
Recommendations For SeedDMS version 5.1.11, consider restricting the ability to create new groups or limiting the input for the GROUP Name field until a patch is available. As a temporary workaround, avoid using JavaScript payloads in the GROUP Name field to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-12801

Produtos afetados

Seeddms