mayan-edms/mayan-edms on GitLab
Advanced enterprise Free Open Source DMS (document management system).
CVE History
CVE | Published | CVSS v2 | CVSS v3 |
---|---|---|---|
CVE-2018-16405 | 6.1 MEDIUM | 4.3 MEDIUM | |
An issue was discovered in Mayan EDMS before 3.0.2. The Appearance app sets window.location directly, leading to XSS. | |||
CVE-2018-16406 | 6.1 MEDIUM | 4.3 MEDIUM | |
An issue was discovered in Mayan EDMS before 3.0.2. The Cabinets app has XSS via a crafted cabinet label. | |||
CVE-2018-16407 | 6.1 MEDIUM | 4.3 MEDIUM | |
An issue was discovered in Mayan EDMS before 3.0.3. The Tags app has XSS because tag label values are mishandled. |