ZeroHour

CVE-2022-28479

PoC
CVSS 3.1
4.8 medium
EPSS
<1%p46
Published
()
Modified
Description

SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable to stored XSS. An attacker with admin privileges can inject the payload inside the "Role management" menu and then trigger the payload by loading the "Users management" menu

Vendors
seeddms
Products
seeddms
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.