Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sanitize user input allowing attackers with admin privileges to delete arbitrary files on the remote system.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SeedDMS 路径遍历漏洞
Vulnerability Description
SeedDMS(前称LetoDMS和MyDMS)是一套基于PHP和MySql的开源文档管理系统。该系统主要用于存储和共享文档。 SeedDMS 6.0.17版本以及5.1.24版本存在安全漏洞,该漏洞源于容易受到目录遍历的影响,“Log files management”菜单中的“Remove file”功能不会清理用户输入。攻击者利用该漏洞删除远程系统上的任意文件。
CVSS Information
N/A
Vulnerability Type
N/A