PT-2026-69454 · Npm · Directory Server
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
cube-root/directory-serve versions prior to 1.3.8
Description
A stored cross-site scripting (XSS) issue exists where an attacker can inject arbitrary JavaScript into the web interface. This occurs when a file is uploaded with a crafted filename containing HTML attribute-breaking characters. The
lib/helper/html.js file fails to sanitize filenames before embedding them in HTML templates at line 28, which allows the script to execute in the browsers of other users viewing the file listing.Recommendations
Update cube-root/directory-serve to version 1.3.8 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Directory Server