The "Add category" functionality inside the "Global Keywords" menu in "SeedDMS" version 6.0.18 and 5.1.25, is prone to stored XSS which allows an attacker to inject malicious javascript code.
| Software | From | Fixed in |
|---|---|---|
| seeddms / seeddms | 5.1.25 | 5.1.25.x |
| seeddms / seeddms | 6.0.18 | 6.0.18.x |