Headline
GHSA-pwq7-f7f9-cm2j: Dutchoders transfer.sh contains an XSS vulnerability via malicious file upload
dutchcoders Transfer.sh versions 1.4.0 and prior are vulnerable to Cross Site Scripting (XSS) via a malicious document uploaded in transfer.sh. There is a fix commit merged into main for this issue, but an updated version has not yet been released.
Dutchoders transfer.sh contains an XSS vulnerability via malicious file upload
Moderate severity GitHub Reviewed Published Sep 30, 2022 • Updated Oct 1, 2022
Related news
CVE-2022-40931: Fixed improper implementation of content type by blind-intruder · Pull Request #501 · dutchcoders/transfer.sh
dutchcoders Transfer.sh 1.4.0 is vulnerable to Cross Site Scripting (XSS).