CVE-2021-30140
LiquidFiles 3.4.15 has stored XSS through the "send email" functionality when sending a file via email to an administrator. When a file has no extension and contains malicious HTML / JavaScript content (such as SVG with HTML content), the payload is executed upon a click. This is fixed in 3.5.
- Affected products
- Liquidfiles
- Liquidfiles
- = 3.4.15
- Fix
- Available
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 1.4% (70th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2021-04-06
CVE-2021-30140 at NVD
2 known exploits for CVE-2021-30140
Proof-of-concept code and exploit modules indexed by Sploitus