Medium severity4.3NVD Advisory· Published Aug 3, 2021· Updated Jun 17, 2026
CVE-2021-35343
CVE-2021-35343
Description
Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.Ajax.php in SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 allows a remote attacker to edit document name without victim's knowledge, by enticing an authenticated user to visit an attacker's web page.
Affected products
4Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.