Cross-Site Scripting Vulnerability in OpenDocMan by OpenDocMan
CVE-2014-4853
Currently unrated
What is CVE-2014-4853?
A Cross-site Scripting (XSS) vulnerability exists in the odm-init.php file of OpenDocMan prior to version 1.2.7.3. This flaw permits remote authenticated users to maliciously inject arbitrary web scripts or HTML code by manipulating the file name during file uploads. Such an attack could lead to unauthorized actions on behalf of users or exposure of sensitive data, underscoring the need for robust security measures in web applications.
