CVE-2021-37794

A stored cross-site scripting (XSS) vulnerability exists in FileBrowser < v2.16.0 that allows an authenticated user authorized to upload a malicious .svg file which acts as a stored XSS payload. If this stored XSS payload is triggered by an administrator it will trigger malicious OS commands on the server running the FileBrowser instance.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:filebrowser_project:filebrowser:*:*:*:*:*:*:*:*

Information

Published : 2021-08-31 11:15

Updated : 2021-09-08 10:27


NVD link : CVE-2021-37794

Mitre link : CVE-2021-37794


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

filebrowser_project

  • filebrowser