CVE-2022-47415

Publication date

2023-02-07 21:33:56

Family

rapid7

State

PUBLISHED

Description

LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the in-app messaging system (both subject and message bodies).