Seafile
cpe:2.3:a:seafile:seafile:*:*:*:*:*:*:*
- < 12.0.14
A stored Cross-Site Scripting (XSS) vulnerability exists in Seafile version 12.0.10. This vulnerability allows attackers to execute arbitrary code in the context of the victim's browser by injecting malicious payloads through a specific POST parameter in the file API of a repository.
Exploitation of this vulnerability allows for stored Cross-Site Scripting, where injected scripts are executed in the context of the user.
Users can upgrade to Seafile version 12.0.14 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.