The FileExplorer component in GleamTech FileUltimate 6.1.5.0 allows XSS via an SVG document.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://gist.github.com/chppppp/9b003d8416e6d3a89d2873a58af2a95f | third party advisory exploit |