WebFileSys Reflected Cross-Site Scripting Vulnerability
Vulnerability
A reflected cross-site scripting vulnerability has been identified in WebFileSys version 2.31.1. This issue allows user-controlled input to be reflected into HTML and JavaScript contexts without adequate output encoding. As a result, attackers can execute arbitrary JavaScript in the context of the victim's browser.
Impact
Exploitation of this vulnerability could lead to session hijacking, credential theft, or unauthorized actions within the user's authenticated session.
Reproduction
To reproduce this vulnerability, navigate to the WebFileSys login page and inject a JavaScript payload into the affected parameter. After submitting the request, the injected script will be executed in the browser.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
