A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the zip import functionality in the Extension Manager.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HSeeddms
APPSeeddms6.0.32
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2022-44938CRITICAL9.8PL ✓same product
SeedDMS: słaby token resetowania hasła umożliwia przejęcie konta
CVE-2021-33223HIGH8.8same product
An issue discovered in SeedDMS 6.0.15 allows an attacker to escalate privileges via the userid and role parame...
CVE-2019-12744HIGH7.5same product
SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts,...
CVE-2018-12942HIGH8.8same product
SQL injection vulnerability in the "Users management" functionality in SeedDMS (formerly LetoDMS and MyDMS) be...
CVE-2018-12940HIGH8.8same product
Unrestricted file upload vulnerability in "op/op.UploadChunks.php" in SeedDMS (formerly LetoDMS and MyDMS) bef...