R-SOFT SERWIS DMS是R-SOFT SERWIS公司的一款应用服务器产品。 R-SOFT SERWIS DMS v3.19-2832之前版本和v3.17-2580之前版本存在跨站脚本漏洞,该漏洞源于文件上传功能存在存储型跨站脚本漏洞,经过身份验证的攻击者可以将任意HTML和JS注入到正在上传的文件名中,当其他用户访问文件列表或上传状态时将会执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| R-SOFT SERWIS | DMS | < v3.19-2832 |
affected |
< v3.17-2580 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| R-SOFT SERWIS | DMS | 0 ~ v3.19-2832 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-41878 | Insecure Direct Object Reference in R-SOFT DMS | |
| CVE-2026-41880 | OS Command Injection in R-SOFT DMS | |
| CVE-2026-41879 | Weak password hashing in R-SOFT DMS | |
| CVE-2026-41876 | OS Command Injection in R-SOFT DMS |
No comments yet