CVE-2020-9447 describes a cross-site scripting (XSS) vulnerability in GwtUpload 1.0.3, specifically within its file upload functionality. An attacker can exploit this by uploading a file with a malicious filename containing JavaScript, leading to XSS. This medium-severity vulnerability (CVSS 6.1) could allow attackers to steal data or alter website appearance, requiring user interaction for successful exploitation. While no active exploitation or public exploit code is currently known, and community discussion is minimal, organizations using affected GwtUpload versions should be aware of this potential risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.3CPE matchmatch criteria | cpe:2.3:a:gwtupload_project:gwtupload:1.0.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.