CVE-2020-29071 is a critical Cross-Site Scripting (XSS) vulnerability affecting LiquidFiles versions prior to 3.3.19, specifically within its Shares feature. This flaw allows for arbitrary code execution, potentially as root, or sensitive data retrieval due to insecure rendering of uploaded HTML attachments when accessed via the -htmlview URL. With a CVSS score of 9.0 (CRITICAL), it presents a high risk due to low attack complexity and significant impact on confidentiality, integrity, and availability, though it requires user interaction. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it has not been observed in active exploitation, nor has it garnered significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.3.19CPE matchmatch criteria | cpe:2.3:a:liquidfiles:liquidfiles:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.