CVE-2025-25461
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Feb 28, 2025
CWE ID 79
Summary
CVE-2025-25461 is a stored Cross-Site Scripting (XSS) vulnerability affecting SeedDMS version 6.0.29. Malicious users or rogue admins with the "Add Category" permission can exploit this flaw by injecting XSS payloads into the category name field. Once a document is associated with the compromised category, the server stores and fails to properly sanitize or output encode the payload. Consequently, any user who views the affected document will have the XSS code executed in their browser.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.