Medium severity4.3NVD Advisory· Published Aug 3, 2021· Updated Jun 17, 2026
CVE-2021-36542
CVE-2021-36542
Description
Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.LockDocument.php in SeedDMS v5.1.x<5.1.23 and v6.0.x <6.0.16 allows a remote attacker to lock any document without victim's knowledge, by enticing an authenticated user to visit an attacker's web page.
Affected products
4Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.