Stored Cross-Site Scripting Vulnerability in FileBrowser by filebrowser
CVE-2021-37794
5.4MEDIUM
What is CVE-2021-37794?
A stored cross-site scripting vulnerability in FileBrowser allows authenticated users to upload malicious .svg files. If an administrator interacts with this malicious stored payload, it can execute harmful OS commands on the server running FileBrowser. This vulnerability highlights the risks associated with unvalidated file uploads and the potential for escalated access to server resources.
