CVSS Summary
| Score | 8 High |
|---|---|
| Vector | Network |
| Complexity | Low |
| Authentication | Single |
| Confidentiality | Partial |
| Integrity | Partial |
| Availability | Complete |
Last revised:
“Display name” and “Description” fields are not escaped, meaning any tags including script tags can be stored in them.
Current state: Fixed
| Score | 8 High |
|---|---|
| Vector | Network |
| Complexity | Low |
| Authentication | Single |
| Confidentiality | Partial |
| Integrity | Partial |
| Availability | Complete |
Go to the upload form, select a document to upload, set the “Display name” to “photograph of a cute puppy<script>alert(‘xss’)</script>” and set the “Description” to “this is an innocuous description<script>alert(‘xss again’)</script>”.
Update to version 1.2.2.