vendor:
SeedDMS
by:
Nimit Jain
5.4
CVSS
MEDIUM
Persistent Cross-Site Scripting or Stored XSS
79
CWE
Product Name: SeedDMS
Affected Version From: < 5.1.11
Affected Version To:
Patch Exists: YES
Related CWE: CVE-2019-12745
CPE:
Platforms Tested:
2019
Persistent Cross-Site Scripting or Stored XSS in out/out.UsrMgr.php in SeedDMS before 5.1.11
This vulnerability allows an attacker to inject malicious scripts into a website, which are then stored and executed when the targeted user accesses the affected page. In this case, the vulnerability is present in the 'out/out.UsrMgr.php' file in SeedDMS versions prior to 5.1.11. By modifying user details and inserting a script, an attacker can execute arbitrary code on the victim's browser.
Mitigation:
Upgrade to SeedDMS version 5.1.11 or higher. Sanitize user input to prevent script injection.