CVSS Summary
| Score | 8 High | 
|---|---|
| Vector | Network | 
| Complexity | Low | 
| Authentication | Single | 
| Confidentiality | Partial | 
| Integrity | Partial | 
| Availability | Complete | 
Last revised:
“Display name” and “Description” fields are not escaped, meaning any tags including script tags can be stored in them.
Current state: Fixed
| Score | 8 High | 
|---|---|
| Vector | Network | 
| Complexity | Low | 
| Authentication | Single | 
| Confidentiality | Partial | 
| Integrity | Partial | 
| Availability | Complete | 
Go to the upload form, select a document to upload, set the “Display name” to “photograph of a cute puppy<script>alert(‘xss’)</script>” and set the “Description” to “this is an innocuous description<script>alert(‘xss again’)</script>”.
Update to version 1.2.2.