Seafile
cpe:2.3:a:seafile:seafile:*:*:*:*:*:*:*
- 11.0.18-Pro
- 12.0.10
- 12.0.10-Pro
A stored Cross-Site Scripting vulnerability has been identified in Seafile versions 11.0.18-Pro, 12.0.10, and 12.0.10-Pro. This vulnerability allows an authenticated attacker to inject a malicious XSS payload into their username, which is then displayed in notifications and activity feeds.
Exploitation of this vulnerability allows for stored Cross-Site Scripting, where injected scripts are executed in the context of the user viewing the affected notifications or activities.
Users can upgrade to Seafile versions 11.0.19-Pro, 12.0.11, or 12.0.11-Pro to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.