A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by storing malicious payloads with POST parámetro 'p' in '/api/v2.1/repos/{repo_id}/file/'.
History

Sat, 06 Dec 2025 00:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:seafile:seafile:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Thu, 04 Dec 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Seafile
Seafile seafile
Vendors & Products Seafile
Seafile seafile

Thu, 04 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 04 Dec 2025 12:00:00 +0000

Type Values Removed Values Added
Description A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by storing malicious payloads with POST parámetro 'p' in '/api/v2.1/repos/{repo_id}/file/'.
Title Multiple vulnerabilities in Seafile
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2025-12-04T11:48:44.776Z

Updated: 2025-12-04T14:43:13.952Z

Reserved: 2025-04-16T09:09:35.597Z

Link: CVE-2025-41080

cve-icon Vulnrichment

Updated: 2025-12-04T14:43:02.913Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-04T12:16:22.153

Modified: 2025-12-05T23:47:30.160

Link: CVE-2025-41080

cve-icon Redhat

No data.