CVE-2014-4853
OpenDocMan <1.2.7.3 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in odm-init.php in OpenDocMan before 1.2.7.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name of an uploaded file.
References (4)
Scores
EPSS
0.0026
EPSS Percentile
48.7%
Details
CWE
CWE-79
Status
published
Products (14)
opendocman/opendocman
< 1.2.7.2
opendocman/opendocman
opendocman/opendocman
opendocman/opendocman
opendocman/opendocman
opendocman/opendocman
opendocman/opendocman
opendocman/opendocman
opendocman/opendocman
opendocman/opendocman
... and 4 more
Published
Jul 10, 2014
Tracked Since
Feb 18, 2026