Impact
An authenticated stored cross‑site scripting Upload File Shares API of LiquidFiles version 4.2.7. The flaw allows an attacker who has valid credentials to inject arbitrary JavaScript or HTML into the Name field, which is then rendered later in the user interface. When the stored name is displayed, the same privileges as the authenticated user.
Affected Systems
LiquidFiles version 4.2.7 is the only release known to contain the vulnerability. No other versions or product lines have been documented as affected.
Risk and Exploitability
Exploitation requires authentication and access to the Upload File Shares API. Once an attacker provides a malicious payload, it is stored and executed whenever the name is rendered, affecting only users who can see the value. The CVSS score of 5.4 indicates moderate severity, while the very low EPSS score (< 1 %) suggests a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no publicly known exploits at the time of reporting.
OpenCVE Enrichment