A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by storing malicious payloads with PUT parámetro 'name' in '/api/v2.1/user/'.
History

Sat, 06 Dec 2025 00:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:seafile:seafile:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Thu, 04 Dec 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Seafile
Seafile seafile
Vendors & Products Seafile
Seafile seafile

Thu, 04 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 04 Dec 2025 12:00:00 +0000

Type Values Removed Values Added
Description A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by storing malicious payloads with PUT parámetro 'name' in '/api/v2.1/user/'.
Title Multiple vulnerabilities in Seafile
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2025-12-04T11:48:10.112Z

Updated: 2025-12-04T14:44:00.913Z

Reserved: 2025-04-16T09:09:35.597Z

Link: CVE-2025-41079

cve-icon Vulnrichment

Updated: 2025-12-04T14:43:46.273Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-04T12:16:20.667

Modified: 2025-12-05T23:48:01.770

Link: CVE-2025-41079

cve-icon Redhat

No data.