PT-2026-57146 · Unknown · R-Soft Dms
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
R-SOFT DMS versions prior to v3.19-2832
R-SOFT DMS versions prior to v3.17-2580
Description
The file upload functionality allows an authenticated attacker to perform Stored Cross-Site Scripting (XSS), a technique where malicious scripts are permanently stored on the target server. By injecting arbitrary HTML and JavaScript into the name of an uploaded file, the script will execute when other users view the file list or the upload status.
Recommendations
Update to version v3.19-2832 or later.
Update to version v3.17-2580 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
R-Soft Dms