CVE-2023-28874: Seafile
Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.
The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary sites.
Affected products
- Seafile Seafile: version 9.0.6 only
Published 2023-12-09. Last modified 2026-06-17.