PoC Index

CVE-2022-28479

MEDIUM 4.8EPSS 0.6%

SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable to stored XSS. An attacker with admin privileges can inject the payload inside the "Role management" menu and then trigger the payload by loading the "Users management" menu

CVSS v3.1
4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
0.58% chance of exploitation in the next 30 days, 46th percentile
Published
2022-06-06
Updated
2024-08-03

Proof-of-concept exploits (1)

References

Related