CVE-2023-28874: Seafile

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary sites.

Affected products

  • Seafile Seafile: version 9.0.6 only

Published 2023-12-09. Last modified 2026-06-17.