39
Views
1
Comments
Solved
[OutSystems UI Web] FileUpload - vulnerability
outsystems-ui-web
Web icon
Forge asset by OutSystems
Application Type
Traditional Web

Hi,

The FileUpload web block, used to masks the File upload widget is vulnerable to a Reflected Cross-Site Scripting attack when a user uploads a file with a payload filename(file name e.g. - <img src=x onerror=alert(“XSS”)>).
The file name is not being sanitized.

Thank you

2022-11-12 11-28-30
Gonçalo Martins
Staff
Solution

Hello @José Pais 

First of all, thanks for reaching out. 
This vulnerability is already in the backlog to be tackled on the next release under the code ROU-4661 for reference in the release notes.

Cheers,
GM

Community GuidelinesBe kind and respectful, give credit to the original source of content, and search for duplicates before posting.