CVE-2026-61504

Rejetto HFS 3.0.0 through 3.2.0 does not escape file names in its fallback "basic" web listing, and this listing can be forced by any browser via the ?get=basic parameter. A user with upload permission - or an anonymous user on servers with an open upload folder - can store a file whose name contains script that executes in the browser of anyone viewing the listing.
Configurations

No configuration.

History

13 Jul 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-13 18:16

Updated : 2026-07-14 23:17


NVD link : CVE-2026-61504

Mitre link : CVE-2026-61504

CVE.ORG link : CVE-2026-61504


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')