CVE-2020-29456

MEDIUM

Papermerge < 1.5.2 - Stored Cross-Site Scripting via Rename, Tag, Upload, or Create Folder Function

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in Papermerge before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the rename, tag, upload, or create folder function. The payload can be in a folder, a tag, or a document's filename. If email consumption is configured in Papermerge, a malicious document can be sent by email and is automatically uploaded into the Papermerge web application. Therefore, no authentication is required to exploit XSS if email consumption is configured. Otherwise authentication is required.

References (3)

Core 3
Core References
Product x_refsource_misc
https://www.papermerge.com/
Third Party Advisory x_refsource_misc
https://github.com/ciur/papermerge/issues/228
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/ciur/papermerge/releases/tag/v1.5.2

Scores

CVSS v3 6.1
EPSS 0.0153
EPSS Percentile 72.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
papermerge/papermerge < 1.5.2
pypi/papermerge 1.2.0 - 1.5.2PyPI
Published Dec 02, 2020
Tracked Since Feb 18, 2026