Zrlog · Zrlog · CVE-2018-17421
**Name of the Vulnerable Software and Affected Versions**
ZrLog version 2.0.3
**Description**
An issue was discovered in the file upload area, where a stored XSS attack can be performed via a crafted attached/file/ pathname.
**Recommendations**
For ZrLog version 2.0.3, consider restricting access to the file upload feature until a fix is available, and avoid using crafted pathnames in the attached/file/ area to minimize the risk of exploitation.