SeedDMS Content Management System v6.0.7 contains a persistent cross-site scripting (XSS) vulnerability in the component AddEvent.php via the name and comment parameters.
| Software | From | Fixed in |
|---|---|---|
| seeddms / seeddms | 6.0.7 | 6.0.7.x |
| seeddms / seeddms | 4.3.37 | 4.3.37.x |
| seeddms / seeddms | 5.0.13 | 5.0.13.x |
| seeddms / seeddms | 5.1.18 | 5.1.18.x |
| seeddms / seeddms | 5.1.16 | 5.1.16.x |
| seeddms / seeddms | 5.1.14 | 5.1.14.x |