5.4
CVSSv3

CVE-2021-30146

Published: 06/04/2021 Updated: 12/04/2021
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

seafile seafile 7.0.5

Vendor Advisories

Debian Bug report logs - #987282 CVE-2021-30146 Package: src:seafile-client; Maintainer for src:seafile-client is Debian Seafile Team <team+seafile@trackerdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 20 Apr 2021 19:00:04 UTC Severity: important Tags: security Reply or subscribe to t ...

Github Repositories

Seafile 7.0.5 Persistent XSS

CVE-2021-30146 Seafile 705 Persistent XSS [Suggested description]: Application (Server Version: 705 Seafile) is vulnerable to Persistent XSS via share library functionality [Additional Information]: Seafile is an open source, self-hosted file sync and share solution with high performance and reliability [Vulnerability Type]: Cross Site Scripting (XSS) A letter was sent to