Seeddms
by Seeddms
CVEs (33)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-45408 | 0.00 | — | 0.01 | Feb 4, 2022 | Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect users to malicious sites using the "referuri" parameter. | |||
| CVE-2020-23048 | 0.00 | — | 0.01 | Oct 22, 2021 | SeedDMS Content Management System v6.0.7 contains a persistent cross-site scripting (XSS) vulnerability in the component AddEvent.php via the name and comment parameters. | |||
| CVE-2021-36543 | 0.00 | — | 0.01 | Aug 3, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.UnlockDocument.php in SeedDMS v5.1.x <5.1.23 and v6.0.x <6.0.16 allows a remote attacker to unlock any document without victim's knowledge, by enticing an authenticated user to visit an attacker's web page. | |||
| CVE-2021-36542 | 0.00 | — | 0.01 | Aug 3, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.LockDocument.php in SeedDMS v5.1.x<5.1.23 and v6.0.x <6.0.16 allows a remote attacker to lock any document without victim's knowledge, by enticing an authenticated user to visit an attacker's web page. | |||
| CVE-2021-35343 | 0.00 | — | 0.01 | Aug 3, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.Ajax.php in SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 allows a remote attacker to edit document name without victim's knowledge, by enticing an authenticated user to visit an attacker's web page. | |||
| CVE-2021-26216 | 0.00 | — | 0.01 | Mar 18, 2021 | SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php. | |||
| CVE-2021-26215 | 0.00 | — | 0.01 | Mar 18, 2021 | SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditDocument.php. | |||
| CVE-2020-28727 | 0.00 | — | 0.01 | Dec 7, 2020 | Cross-site scripting (XSS) exists in SeedDMS 6.0.13 via the folderid parameter to views/bootstrap/class.DropFolderChooser.php. | |||
| CVE-2020-28726 | 0.00 | — | 0.01 | Nov 24, 2020 | Open redirect in SeedDMS 6.0.13 via the dropfolderfileform1 parameter to out/out.AddDocument.php. | |||
| CVE-2019-12932 | 0.00 | — | 0.01 | Jun 28, 2019 | A stored XSS vulnerability was found in SeedDMS 5.1.11 due to poorly escaping the search result in the autocomplete search form placed in the header of out/out.Viewfolder.php. | |||
| CVE-2014-2279 | 0.00 | — | 0.05 | Oct 17, 2014 | Multiple directory traversal vulnerabilities in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allow (1) remote authenticated users with access to the LogManagement functionality to read arbitrary files via a .. (dot dot) in the logname parameter to out/out.LogManagement.php… | |||
| CVE-2014-2278 | 0.00 | — | 0.04 | Oct 17, 2014 | Unrestricted file upload vulnerability in op/op.AddFile2.php in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows remote attackers to execute arbitrary code by uploading a file with an executable extension specified by the partitionIndex parameter and leveraging… | |||
| CVE-2014-2280 | 0.00 | — | 0.02 | Mar 20, 2014 | Cross-site scripting (XSS) vulnerability in the search feature in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows remote attackers to inject arbitrary web script or HTML via the query parameter. |
- CVE-2021-45408Feb 4, 2022risk 0.00cvss —epss 0.01
Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect users to malicious sites using the "referuri" parameter.
- CVE-2020-23048Oct 22, 2021risk 0.00cvss —epss 0.01
SeedDMS Content Management System v6.0.7 contains a persistent cross-site scripting (XSS) vulnerability in the component AddEvent.php via the name and comment parameters.
- CVE-2021-36543Aug 3, 2021risk 0.00cvss —epss 0.01
Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.UnlockDocument.php in SeedDMS v5.1.x <5.1.23 and v6.0.x <6.0.16 allows a remote attacker to unlock any document without victim's knowledge, by enticing an authenticated user to visit an attacker's web page.
- CVE-2021-36542Aug 3, 2021risk 0.00cvss —epss 0.01
Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.LockDocument.php in SeedDMS v5.1.x<5.1.23 and v6.0.x <6.0.16 allows a remote attacker to lock any document without victim's knowledge, by enticing an authenticated user to visit an attacker's web page.
- CVE-2021-35343Aug 3, 2021risk 0.00cvss —epss 0.01
Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.Ajax.php in SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 allows a remote attacker to edit document name without victim's knowledge, by enticing an authenticated user to visit an attacker's web page.
- CVE-2021-26216Mar 18, 2021risk 0.00cvss —epss 0.01
SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php.
- CVE-2021-26215Mar 18, 2021risk 0.00cvss —epss 0.01
SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditDocument.php.
- CVE-2020-28727Dec 7, 2020risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) exists in SeedDMS 6.0.13 via the folderid parameter to views/bootstrap/class.DropFolderChooser.php.
- CVE-2020-28726Nov 24, 2020risk 0.00cvss —epss 0.01
Open redirect in SeedDMS 6.0.13 via the dropfolderfileform1 parameter to out/out.AddDocument.php.
- CVE-2019-12932Jun 28, 2019risk 0.00cvss —epss 0.01
A stored XSS vulnerability was found in SeedDMS 5.1.11 due to poorly escaping the search result in the autocomplete search form placed in the header of out/out.Viewfolder.php.
- CVE-2014-2279Oct 17, 2014risk 0.00cvss —epss 0.05
Multiple directory traversal vulnerabilities in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allow (1) remote authenticated users with access to the LogManagement functionality to read arbitrary files via a .. (dot dot) in the logname parameter to out/out.LogManagement.php…
- CVE-2014-2278Oct 17, 2014risk 0.00cvss —epss 0.04
Unrestricted file upload vulnerability in op/op.AddFile2.php in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows remote attackers to execute arbitrary code by uploading a file with an executable extension specified by the partitionIndex parameter and leveraging…
- CVE-2014-2280Mar 20, 2014risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in the search feature in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.
Page 2 of 2