PT-2022-10654 · Unknown · Jquery File Upload

Published

2022-02-25

·

Updated

2024-02-14

·

CVE-2021-37504

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions jQuery-Upload-File version 4.0.11
Description A cross-site scripting (XSS) issue exists due to a vulnerability in the fileNameStr parameter, allowing attackers to execute arbitrary web scripts or HTML via a crafted file with a Javascript payload in the file name.
Recommendations For jQuery-Upload-File version 4.0.11, consider validating and sanitizing the fileNameStr parameter to prevent the execution of malicious scripts. As a temporary workaround, restrict the ability to upload files with potentially malicious names until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-37504
GHSA-43X9-7HFV-MXRF

Affected Products

Jquery File Upload