jQuery-Upload-File XSS in fileNameStr
Moderate severity
GitHub Reviewed
Published
Feb 26, 2022
to the GitHub Advisory Database
•
Updated Apr 2, 2024
Description
Published by the National Vulnerability Database
Feb 25, 2022
Published to the GitHub Advisory Database
Feb 26, 2022
Reviewed
Apr 2, 2024
Last updated
Apr 2, 2024
A cross-site scripting (XSS) vulnerability in the fileNameStr parameter of jQuery-Upload-File v4.0.11 allows attackers to execute arbitrary web scripts or HTML via a crafted file with a Javascript payload in the file name.
References