Advisories for Pypi/Papermerge package

2020

Cross-site Scripting

Multiple cross-site scripting (XSS) vulnerabilities in Papermerge allow remote attackers to inject arbitrary web script or HTML via the rename, tag, upload, or create folder function. The payload can be in a folder, a tag, or a document's filename. If email consumption is configured in Papermerge, a malicious document can be sent by email and is automatically uploaded into the Papermerge web application. Therefore, no authentication is required to exploit …