CVSS Summary
Score | 8 High |
---|---|
Vector | Network |
Complexity | Low |
Authentication | Single |
Confidentiality | Partial |
Integrity | Partial |
Availability | Complete |
Last revised:
“Display name” and “Description” fields are not escaped, meaning any tags including script tags can be stored in them.
Current state: Fixed
Score | 8 High |
---|---|
Vector | Network |
Complexity | Low |
Authentication | Single |
Confidentiality | Partial |
Integrity | Partial |
Availability | Complete |
Go to the upload form, select a document to upload, set the “Display name” to “photograph of a cute puppy<script>alert(‘xss’)</script>” and set the “Description” to “this is an innocuous description<script>alert(‘xss again’)</script>”.
Update to version 1.2.2.