Security Advisory

CVE-2025-45091

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-09-15 00:00:00
Last updated 2025-09-15 20:09:23
Assigner mitre
State PUBLISHED

Description

Seafile versions 11.0.18-Pro, 12.0.10, and 12.0.10-Pro are vulnerable to a stored Cross-Site Scripting (XSS) attack. An authenticated attacker can exploit this vulnerability by modifying their username to include a malicious XSS payload in notification and activities.