CyberRota Analysis
AI-GeneratedAn authenticated stored cross-site scripting vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to inject malicious JavaScript or HTML through the Name parameter, potentially compromising user sessions or data integrity. Organizations utilizing this version of LiquidFiles should prioritize remediation to mitigate the risk of exploitation, particularly those handling sensitive information or user interactions through the affected API.
Original NVD Description
An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbitrary Javascript or HTML via injecting a crafted payload into the Name parameter.