CVE-2025-25461

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Feb 28, 2025
CWE ID 79

Summary

CVE-2025-25461 is a stored Cross-Site Scripting (XSS) vulnerability affecting SeedDMS version 6.0.29. Malicious users or rogue admins with the "Add Category" permission can exploit this flaw by injecting XSS payloads into the category name field. Once a document is associated with the compromised category, the server stores and fails to properly sanitize or output encode the payload. Consequently, any user who views the affected document will have the XSS code executed in their browser.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share