PT-2023-22023 · Seafile · Seafile
CVE-2023-28873
·
Publicado
2023-12-08
·
Atualizado
2023-12-12
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Seafile version 9.0.6
Description
An issue allows attackers to inject JavaScript into the Markdown editor in wiki and discussion pages. This is achieved through an XSS issue, which enables the execution of malicious scripts.
Recommendations
For Seafile version 9.0.6, update to a version that includes a fix for this issue to prevent JavaScript injection into the Markdown editor.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Seafile