WebFileSys Reflected Cross-Site Scripting Vulnerability

Vulnerability

A reflected cross-site scripting vulnerability has been identified in WebFileSys version 2.31.1. This issue allows user-controlled input to be reflected into HTML and JavaScript contexts without adequate output encoding. As a result, attackers can execute arbitrary JavaScript in the context of the victim's browser.

Impact

Exploitation of this vulnerability could lead to session hijacking, credential theft, or unauthorized actions within the user's authenticated session.

Reproduction

To reproduce this vulnerability, navigate to the WebFileSys login page and inject a JavaScript payload into the affected parameter. After submitting the request, the injected script will be executed in the browser.

Added: Apr 27, 2026, 9:21 PM
Updated: Apr 27, 2026, 9:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
7.5
remediation
0.0
relevance
6.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.