A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by storing malicious payloads with PUT parámetro 'name' in '/api/v2.1/user/'.
Metrics
Affected Vendors & Products
References
History
Sat, 06 Dec 2025 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:seafile:seafile:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Thu, 04 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Seafile
Seafile seafile |
|
| Vendors & Products |
Seafile
Seafile seafile |
Thu, 04 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Dec 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by storing malicious payloads with PUT parámetro 'name' in '/api/v2.1/user/'. | |
| Title | Multiple vulnerabilities in Seafile | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-12-04T11:48:10.112Z
Updated: 2025-12-04T14:44:00.913Z
Reserved: 2025-04-16T09:09:35.597Z
Link: CVE-2025-41079
Updated: 2025-12-04T14:43:46.273Z
Status : Analyzed
Published: 2025-12-04T12:16:20.667
Modified: 2025-12-05T23:48:01.770
Link: CVE-2025-41079
No data.