MEDIUM
Mayan EDMS Tag XSS
Published Feb 7, 2023
5.1
MEDIUMCVSS 4.0
EPSS 0.54%
Description
An XSS vulnerability was discovered in the Mayan EDMS DMS. Successful XSS exploitation was observed in the in-product tagging system.
Affected products
-
- Version 4.3.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mayan EDMS | Mayan EDMS | affected |
|
- 4.3.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-0142 Advisory
- https://github.com/advisories/GHSA-5m6v-2xgf-qhrw Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/mayan-edms/PYSEC-2023-276.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2022-47419
- https://www.mayan-edms.com/news/2023/02/version-4.3.6 release-notesvendor-advisory
- https://www.rapid7.com/blog/post/2023/02/07/multiple-dms-xss-cve-2022-47412-through-cve-20222-47419 third-party-advisoryExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-0142 | Advisory | |
| https://github.com/advisories/GHSA-5m6v-2xgf-qhrw | Advisory | |
| https://github.com/pypa/advisory-database/tree/main/vulns/mayan-edms/PYSEC-2023-276.yaml | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-47419 | ||
| https://www.mayan-edms.com/news/2023/02/version-4.3.6 | release-notesvendor-advisory | |
| https://www.rapid7.com/blog/post/2023/02/07/multiple-dms-xss-cve-2022-47412-through-cve-20222-47419 | third-party-advisoryExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner rapid7
Published Feb 7, 2023
Updated Mar 25, 2025
Reserved Dec 14, 2022
Link CVE-2022-47419
CISA Vulnrichment
Updated Mar 25, 2025
ENISA EUVD
EUVD-2023-0142 GHSA-5M6V-2XGF-QHRW Assigner rapid7
Published Feb 7, 2023
Updated Mar 25, 2025
Exploited since n/a
Link EUVD-2023-0142