Medium severity6.1NVD Advisory· Published Sep 3, 2018· Updated Jun 17, 2026
CVE-2018-16405
CVE-2018-16405
Description
An issue was discovered in Mayan EDMS before 3.0.2. The Appearance app sets window.location directly, leading to XSS.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mayan-edmsPyPI | < 3.0.2 | 3.0.2 |
mayan-edms-ngPyPI | < 3.0.2 | 3.0.2 |
Affected products
2- ghsa-coords2 versions
< 3.0.2+ 1 more
- (no CPE)range: < 3.0.2
- (no CPE)range: < 3.0.2
Patches
Vulnerability mechanics
References
7- gitlab.com/mayan-edms/mayan-edms/commit/9ebe80595afe4fdd1e2c74358d6a9421f4ce130envdPatchThird Party AdvisoryWEB
- gitlab.com/mayan-edms/mayan-edms/issues/494nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-fpcv-j2q9-vqhwghsaADVISORY
- gitlab.com/mayan-edms/mayan-edms/blob/master/HISTORY.rstnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-16405ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/mayan-edms-ng/PYSEC-2018-16.yamlghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/mayan-edms/PYSEC-2018-106.yamlghsaWEB
News mentions
0No linked articles in our index yet.