CVE-2022-0967

MEDIUM6.9EPSS 0.83%

Stored Cross-site Scripting in showdoc

Published: 3/16/2022Modified: 11/8/2023

Description

ShowDoc is a tool for an IT team to share documents online. showdoc contains a stored cross-site scripting vulnerability in the File Library page when uploading a file in .ofd format in versions prior to 2.10.4. At this time, there is no known workaround. Users should update to version 2.10.4.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.9CVSS:3.0/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

References (4)