CyberRota Analysis
AI-GeneratedAn HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to upload malicious HTML files, enabling the execution of arbitrary JavaScript in the victim's browser. This could lead to unauthorized actions or data exposure for users interacting with the compromised content. Organizations using this version of LiquidFiles should prioritize patching to mitigate potential exploitation risks.
Original NVD Description
An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in the context of the victim's browser via the uploading of and user interaction with a crafted HTML file.