PT-2026-40445 · Efw · Efw
Published
2026-05-12
·
Updated
2026-05-13
·
CVE-2026-44259
CVSS v3.1
4.6
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
efw4.X versions prior to 4.08.010
Description
The 'previewServlet' serves files using detected MIME types based on file extensions without applying security headers or content sanitization. Files with extensions such as .html, .htm, or .svg are served as 'text/html' or 'image/svg+xml', which allows embedded JavaScript to execute in the user's browser within the application's origin.
Recommendations
Update to version 4.08.010.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Efw