CVE-2008-7231

Meridio Document and Records Management <4.3 SR1 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in Meridio Document and Records Management before 4.3 SR1 allows remote authenticated users to inject arbitrary web script or HTML via the Title field in a (1) document (subGeneralProps:dmpvDocTitle:PROP_W_title) or (2) container (subGeneralProps:dmpvContainerTitle:PROP_W_title).

Scores

EPSS 0.0020
EPSS Percentile 42.0%

Classification

CWE
CWE-79
Status published

Affected Products (3)

meridio/document_and_records_management < 4.3
meridio/document_and_records_management
n/a/n/a

Timeline

Published Sep 14, 2009
Tracked Since Feb 18, 2026