PT-2022-19052 · Seeddms · Seeddms

Loociprian

·

Published

2022-06-06

·

Updated

2022-06-14

·

CVE-2022-28479

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SeedDMS versions 6.0.18 and 5.1.25 and below
Description The issue allows an attacker with admin privileges to inject a payload inside the "Role management" menu and then trigger the payload by loading the "Users management" menu, resulting in stored XSS.
Recommendations For SeedDMS versions 6.0.18 and below, and 5.1.25 and below, consider disabling access to the "Role management" and "Users management" menus until a patch is available. As a temporary workaround, restrict the use of admin privileges to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-28479

Affected Products

Seeddms