-
Type:
Public Security Vulnerability
-
Resolution: Fixed
-
Priority:
Low
-
Affects Version/s: 4.8.12
-
Component/s: None
-
None
-
6.4
-
Medium
Crucible server is vulnerable to stored xss via file upload within certain endpoint A malicious, authenticated user with the ability to modify reviews can upload a malicious php file with an XSS payload.