Multiple vulnerabilities in Seafile
Vulnerability Description
A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by storing malicious payloads with PUT parámetro 'name' in '/api/v2.1/user/'.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41079
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Arnau Sola López and Arnau Yepes Huguet
More from Seafile
View All →Affected Vendor
Seafile
View all reports →