Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-pwq7-f7f9-cm2j: Dutchoders transfer.sh contains an XSS vulnerability via malicious file upload

dutchcoders Transfer.sh versions 1.4.0 and prior are vulnerable to Cross Site Scripting (XSS) via a malicious document uploaded in transfer.sh. There is a fix commit merged into main for this issue, but an updated version has not yet been released.

ghsa
#xss#vulnerability#git

Dutchoders transfer.sh contains an XSS vulnerability via malicious file upload

Moderate severity GitHub Reviewed Published Sep 30, 2022 • Updated Oct 1, 2022

Related news

CVE-2022-40931: Fixed improper implementation of content type by blind-intruder · Pull Request #501 · dutchcoders/transfer.sh

dutchcoders Transfer.sh 1.4.0 is vulnerable to Cross Site Scripting (XSS).