An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbitrary Javascript or HTML via injecting a crafted payload into the Name parameter.
An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbitrary Javascript or HTML via injecting a crafted payload into the Name parameter.
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 54.00 |
| Exploitation signal(No additional exploitation signal) | ×1.00 |
| VPI | 54.00 |
VPI formula vpi-v1