CVE-2022-28479

MEDIUM

SeedDMS <= 6.0.18 and <= 5.1.25 - Authenticated Stored Cross-Site Scripting in Role Management

Title source: llm
STIX 2.1

Description

SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable to stored XSS. An attacker with admin privileges can inject the payload inside the "Role management" menu and then trigger the payload by loading the "Users management" menu

Scores

CVSS v3 4.8
EPSS 0.0056
EPSS Percentile 42.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
seeddms/seeddms 5.1.25
seeddms/seeddms 6.0.18
Published Jun 06, 2022
Tracked Since Feb 18, 2026