Medium severity6.1NVD Advisory· Published Oct 23, 2017· Updated May 13, 2026
CVE-2012-4567
CVE-2012-4567
Description
Multiple cross-site scripting (XSS) vulnerabilities in LetoDMS (formerly MyDMS) before 3.3.8 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) inc/inc.ClassUI.php or (2) out/out.DocumentNotify.php.
Affected products
8cpe:2.3:a:letodms_project:letodms:3.3.0:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:letodms_project:letodms:3.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:letodms_project:letodms:3.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:letodms_project:letodms:3.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:letodms_project:letodms:3.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:letodms_project:letodms:3.3.4:*:*:*:*:*:*:*
- cpe:2.3:a:letodms_project:letodms:3.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:letodms_project:letodms:3.3.6:*:*:*:*:*:*:*
- cpe:2.3:a:letodms_project:letodms:3.3.7:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.securityfocus.com/bid/55822nvdThird Party AdvisoryVDB Entry
- sourceforge.net/p/mydms/code/HEAD/tree/trunk/CHANGELOGnvdIssue TrackingRelease Notes
- www.openwall.com/lists/oss-security/2012/10/06/1nvdMailing List
- www.openwall.com/lists/oss-security/2012/10/31/7nvdMailing List
News mentions
0No linked articles in our index yet.