VDB
Sign up
MEDIUM6.1

GHSA-43x9-7hfv-mxrf

jQuery-Upload-File XSS in fileNameStr

Details

A cross-site scripting (XSS) vulnerability in the fileNameStr parameter of jQuery-Upload-File v4.0.11 allows attackers to execute arbitrary web scripts or HTML via a crafted file with a Javascript payload in the file name.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jquery-file-upload
Introduced in: 0

No fixed version published yet for jquery-file-upload (npm). Pin to a known-safe version or switch to an alternative.

References