Stored XSS Vulnerability in Croogo File Manager
CVE-2019-7173
4.8MEDIUM
What is CVE-2019-7173?
A stored Cross-Site Scripting (XSS) vulnerability exists in Croogo versions up to 3.0.5, specifically within the Title field of the file manager's attachment editing page. An attacker can exploit this flaw to inject malicious HTML or JavaScript code, which could be executed in the context of an unsuspecting user's session, potentially leading to data theft or other malicious activities.
