VDB
Sign up
MEDIUM5.4

PYSEC-2023-276

Quick fix

PYSEC-2023-276 — mayan-edms: upgrade to the fixed version with the command below.

pip install --upgrade 'mayan-edms>=4.3.6'

Details

An XSS vulnerability was discovered in the Mayan EDMS DMS. Successful XSS exploitation was observed in the in-product tagging system.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/mayan-edms
Introduced in: 0Fixed in: 4.3.6
Fixpip install --upgrade 'mayan-edms>=4.3.6'

References