WiFi File Transfer Cross-Site Scripting Vulnerability

Vulnerability

A persistent cross-site scripting vulnerability has been identified in WiFi File Transfer version 1.0.8. This vulnerability allows remote attackers to inject malicious scripts into file and folder names. Exploitation occurs when users preview these infected file paths, potentially hijacking their browser sessions.

Impact

Exploitation of this vulnerability allows for session hijacking and the execution of injected scripts in the context of the user's browser.

Reproduction

The vulnerability can be reproduced by installing WiFi File Transfer version 1.0.8 on an Android device. Once the application is running and the WiFi web server is active, an attacker can access the web interface through a browser. By injecting a script payload into the file or folder name and saving it, the injected script will execute when the path is previewed.

Remediation

To address this vulnerability, input validation should be improved by restricting file and folder names to disallow special characters. Additionally, the application should sanitize and encode the content of the data_file parameter before processing, and filter output paths to prevent script execution.

Added: Feb 1, 2026, 1:33 PM
Updated: Feb 1, 2026, 1:33 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.0
exploitability
6.0
remediation
0.0
relevance
2.6
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.