Impact
An attacker who has valid credentials can upload a specially crafted HTML file to LiquidFiles 4.2.7. When a user later opens that file in a browser, the embedded JavaScript runs within the victim’s browser context, enabling the attacker to execute arbitrary code in the victim’s session. The vulnerability is an HTML injection flaw that results in stored XSS.
Affected Systems
LiquidFiles 4.2.7 is affected. No other product versions are mentioned.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low probability of widespread exploitation. Exploitation requires the attacker to obtain valid user credentials to upload the malicious file, so the attack vector is authenticated.
OpenCVE Enrichment