Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Seafile versions 11.0.18-Pro, 12.0.10, and 12.0.10-Pro are vulnerable to a stored Cross-Site Scripting (XSS) attack. An authenticated attacker can exploit this vulnerability by modifying their username to include a malicious XSS payload in notification and activities.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Seafile 安全漏洞
Vulnerability Description
Seafile是中国海文互知网络技术(Seafile)公司的一款开源的企业云盘。该产品具有Markdown WYSIWYG编辑,Wiki,文件标签等功能。 Seafile 11.0.18-Pro版本、12.0.10版本和12.0.10-Pro版本存在安全漏洞,该漏洞源于修改用户名时可嵌入恶意XSS有效载荷,可能导致存储型跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A