CVE-2008-7231
Meridio Document and Records Management <4.3 SR1 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in Meridio Document and Records Management before 4.3 SR1 allows remote authenticated users to inject arbitrary web script or HTML via the Title field in a (1) document (subGeneralProps:dmpvDocTitle:PROP_W_title) or (2) container (subGeneralProps:dmpvContainerTitle:PROP_W_title).
References (4)
Scores
EPSS
0.0020
EPSS Percentile
42.0%
Classification
CWE
CWE-79
Status
published
Affected Products (3)
meridio/document_and_records_management
< 4.3
meridio/document_and_records_management
n/a/n/a
Timeline
Published
Sep 14, 2009
Tracked Since
Feb 18, 2026