PT-2020-9726 · Fileview · Fileview
Published
2020-01-06
·
Updated
2020-04-01
·
CVE-2019-15602
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
fileview versions 0.1.6 and earlier
fileview (all versions)
Description
The issue is related to inadequate output encoding and escaping in the fileview package, leading to a stored Cross-Site Scripting (XSS) vulnerability in files it serves. This vulnerability allows attackers to execute arbitrary JavaScript in the victim's browser through files with names containing malicious code, as the package fails to sanitize filenames.
Recommendations
For fileview version 0.1.6, consider using an alternative package until a fix is made available.
For all versions of fileview, consider using an alternative package until a fix is made available.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fileview