CVE-2021-30146
MEDIUMSeafile 7.0.5 - Stored Cross-Site Scripting via Library Share Functionality
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-30146. PoCs published by Security-AVS.
AI-analyzed exploit summary The repository describes a Persistent XSS vulnerability in Seafile 7.0.5, where an attacker with a local account can share a malicious library, executing JavaScript via notification messages in victim accounts. The README provides a technical overview but lacks exploit code or detailed analysis.
Description
Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."
Exploits (1)
The repository describes a Persistent XSS vulnerability in Seafile 7.0.5, where an attacker with a local account can share a malicious library, executing JavaScript via notification messages in victim accounts. The README provides a technical overview but lacks exploit code or detailed analysis.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N