Executive brief
An issue was discovered in Mayan EDMS before 3.0.2. The Appearance app sets window.location directly, leading to XSS.
Affected products
- PyPI mayan-edms
- PyPI mayan-edms-ng
Junglewise Threat Intelligence
CVE-2018-16405 · Severity: low · CVSS 3 · Published 2018-09-03
Technologies: mayan-edms (PyPI). Vendors: PyPI.
An issue was discovered in Mayan EDMS before 3.0.2. The Appearance app sets window.location directly, leading to XSS.