PT-2026-5114 · Unknown · Pdw File Browser
David Bimmel
·
Published
2026-01-28
·
Updated
2026-01-28
·
CVE-2020-36988
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PDW File Browser versions 1.3 and earlier
Description
PDW File Browser versions 1.3 and earlier are susceptible to stored and reflected cross-site scripting issues. Authenticated attackers can inject malicious scripts through file rename and path parameters. Attackers can create malicious URLs or rename files containing XSS payloads to execute arbitrary JavaScript in the browsers of users accessing the file browser. The vulnerable parameters include file rename and path parameters.
Recommendations
Versions prior to 1.3 are vulnerable.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pdw File Browser