VYPR

Seeddms

by Seeddms

CVEs (33)

  • CVE-2021-45408Feb 4, 2022
    risk 0.00cvss epss 0.01

    Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect users to malicious sites using the "referuri" parameter.

  • CVE-2020-23048Oct 22, 2021
    risk 0.00cvss epss 0.01

    SeedDMS Content Management System v6.0.7 contains a persistent cross-site scripting (XSS) vulnerability in the component AddEvent.php via the name and comment parameters.

  • CVE-2021-36543Aug 3, 2021
    risk 0.00cvss epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.UnlockDocument.php in SeedDMS v5.1.x <5.1.23 and v6.0.x <6.0.16 allows a remote attacker to unlock any document without victim's knowledge, by enticing an authenticated user to visit an attacker's web page.

  • CVE-2021-36542Aug 3, 2021
    risk 0.00cvss epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.LockDocument.php in SeedDMS v5.1.x<5.1.23 and v6.0.x <6.0.16 allows a remote attacker to lock any document without victim's knowledge, by enticing an authenticated user to visit an attacker's web page.

  • CVE-2021-35343Aug 3, 2021
    risk 0.00cvss epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.Ajax.php in SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 allows a remote attacker to edit document name without victim's knowledge, by enticing an authenticated user to visit an attacker's web page.

  • CVE-2021-26216Mar 18, 2021
    risk 0.00cvss epss 0.01

    SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php.

  • CVE-2021-26215Mar 18, 2021
    risk 0.00cvss epss 0.01

    SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditDocument.php.

  • CVE-2020-28727Dec 7, 2020
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) exists in SeedDMS 6.0.13 via the folderid parameter to views/bootstrap/class.DropFolderChooser.php.

  • CVE-2020-28726Nov 24, 2020
    risk 0.00cvss epss 0.01

    Open redirect in SeedDMS 6.0.13 via the dropfolderfileform1 parameter to out/out.AddDocument.php.

  • CVE-2019-12932Jun 28, 2019
    risk 0.00cvss epss 0.01

    A stored XSS vulnerability was found in SeedDMS 5.1.11 due to poorly escaping the search result in the autocomplete search form placed in the header of out/out.Viewfolder.php.

  • CVE-2014-2279Oct 17, 2014
    risk 0.00cvss epss 0.05

    Multiple directory traversal vulnerabilities in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allow (1) remote authenticated users with access to the LogManagement functionality to read arbitrary files via a .. (dot dot) in the logname parameter to out/out.LogManagement.php…

  • CVE-2014-2278Oct 17, 2014
    risk 0.00cvss epss 0.04

    Unrestricted file upload vulnerability in op/op.AddFile2.php in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows remote attackers to execute arbitrary code by uploading a file with an executable extension specified by the partitionIndex parameter and leveraging…

  • CVE-2014-2280Mar 20, 2014
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the search feature in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.

Page 2 of 2