vendor:
Mayan EDMS
by:
Dolev Farhi
8,8
CVSS
HIGH
Stored XSS
79
CWE
Product Name: Mayan EDMS
Affected Version From: 0.13
Affected Version To: 0.13
Patch Exists: YES
Related CWE: N/A
CPE: mayan-edms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Kali Linux
2014
Multiple Stored XSS
An attacker is able to create documents and tags with malicious code, potentially stealing admin cookies browsing or editing the documents. Steps to reproduce include creating tags, sources, staging folders, bootstrap setups, and smart links with malicious code.
Mitigation:
Ensure that user-supplied input is properly sanitized and validated before being used in the application.