{"api_version":"1","generated_at":"2026-07-23T06:57:50+00:00","cve":"CVE-2018-12943","urls":{"html":"https://cve.report/CVE-2018-12943","api":"https://cve.report/api/cve/CVE-2018-12943.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-12943","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-12943"},"summary":{"title":"CVE-2018-12943","description":"Cross-Site Scripting (XSS) vulnerability in every page that includes the \"action\" URL parameter in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-07-31 14:29:00","updated_at":"2018-10-04 22:14:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://www.contextis.com/resources/advisories/cve-2018-12943","name":"https://www.contextis.com/resources/advisories/cve-2018-12943","refsource":"MISC","tags":["Third Party Advisory"],"title":"CVE-2018-12943 | Context Information Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://sourceforge.net/p/seeddms/code/ci/seeddms-5.1.x/tree/CHANGELOG","name":"https://sourceforge.net/p/seeddms/code/ci/seeddms-5.1.x/tree/CHANGELOG","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"seeddms / Code /\n  [2c013b]\n  /CHANGELOG","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-12943","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-12943","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"12943","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"seeddms","cpe5":"seeddms","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"12943","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"seeddms","cpe5":"seeddms","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-12943","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-Site Scripting (XSS) vulnerability in every page that includes the \"action\" URL parameter in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://www.contextis.com/resources/advisories/cve-2018-12943","refsource":"MISC","url":"https://www.contextis.com/resources/advisories/cve-2018-12943"},{"name":"https://sourceforge.net/p/seeddms/code/ci/seeddms-5.1.x/tree/CHANGELOG","refsource":"CONFIRM","url":"https://sourceforge.net/p/seeddms/code/ci/seeddms-5.1.x/tree/CHANGELOG"}]}},"nvd":{"publishedDate":"2018-07-31 14:29:00","lastModifiedDate":"2018-10-04 22:14:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:seeddms:seeddms:*:*:*:*:*:*:*:*","versionEndExcluding":"5.1.8","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"12943","Ordinal":"129591","Title":"CVE-2018-12943","CVE":"CVE-2018-12943","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"12943","Ordinal":"1","NoteData":"Cross-Site Scripting (XSS) vulnerability in every page that includes the \"action\" URL parameter in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"12943","Ordinal":"2","NoteData":"2018-07-31","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"12943","Ordinal":"3","NoteData":"2018-07-31","Type":"Other","Title":"Modified"}]}}}