Impact
An HTML injection flaw in LiquidFiles 4.2.7 allows authenticated users to upload a crafted HTML file. When a victim later accesses the file in a browser, the injected script executes in the victim’s browser context, enabling arbitrary JavaScript execution. This stored XSS vulnerability can be used to steal session cookies, manipulate the user interface, and perform actions within the user’s session.
Affected Systems
LiquidFiles 4.2.7 is affected. No other product versions are mentioned.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of widespread exploitation. Exploitation requires an attacker to first obtain valid credentials to upload a malicious file and then rely on a second authorized user to open the file in a browser, thereby decreasing the immediate risk relative to publicly exploitable flaws.
OpenCVE Enrichment