PT-2022-13566 · Showdoc · Showdoc

Published

2022-03-15

·

Updated

2022-07-21

·

CVE-2022-0967

CVSS v3.1

6.9

Medium

VectorAV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions showdoc versions prior to 2.10.4
Description The issue is a stored cross-site scripting vulnerability in the File Library page when uploading a file in .ofd format. showdoc is a tool for an IT team to share documents online. There is no known workaround at this time.
Recommendations For versions prior to 2.10.4, update to version 2.10.4 to resolve the issue. As a temporary workaround, consider restricting file uploads, especially in .ofd format, until the update is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0967
GHSA-3PG8-C473-W6RR

Affected Products

Showdoc