Cross site scripting in Cloudreve
Moderate severity
GitHub Reviewed
Published
Sep 21, 2022
to the GitHub Advisory Database
•
Updated Jul 7, 2023
Description
Published by the National Vulnerability Database
Sep 20, 2022
Published to the GitHub Advisory Database
Sep 21, 2022
Reviewed
Sep 23, 2022
Last updated
Jul 7, 2023
Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functionality. A low privileged user will be able to share a file with an admin user, which could lead to privilege escalation.
References