A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by storing malicious payloads with POST parámetro 'p' in '/api/v2.1/repos/{repo_id}/file/'.
Metrics
Affected Vendors & Products
References
History
Sat, 06 Dec 2025 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:seafile:seafile:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Thu, 04 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Seafile
Seafile seafile |
|
| Vendors & Products |
Seafile
Seafile seafile |
Thu, 04 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Dec 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by storing malicious payloads with POST parámetro 'p' in '/api/v2.1/repos/{repo_id}/file/'. | |
| Title | Multiple vulnerabilities in Seafile | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-12-04T11:48:44.776Z
Updated: 2025-12-04T14:43:13.952Z
Reserved: 2025-04-16T09:09:35.597Z
Link: CVE-2025-41080
Updated: 2025-12-04T14:43:02.913Z
Status : Analyzed
Published: 2025-12-04T12:16:22.153
Modified: 2025-12-05T23:47:30.160
Link: CVE-2025-41080
No data.