CVE-2020-29456
MEDIUMPapermerge < 1.5.2 - Stored Cross-Site Scripting via Rename, Tag, Upload, or Create Folder Function
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Papermerge before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the rename, tag, upload, or create folder function. The payload can be in a folder, a tag, or a document's filename. If email consumption is configured in Papermerge, a malicious document can be sent by email and is automatically uploaded into the Papermerge web application. Therefore, no authentication is required to exploit XSS if email consumption is configured. Otherwise authentication is required.
References (3)
Core 3
Core References
Product x_refsource_misc
https://www.papermerge.com/
Third Party Advisory x_refsource_misc
https://github.com/ciur/papermerge/issues/228
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/ciur/papermerge/releases/tag/v1.5.2
Scores
CVSS v3
6.1
EPSS
0.0153
EPSS Percentile
72.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
papermerge/papermerge
< 1.5.2
pypi/papermerge
1.2.0 - 1.5.2PyPI
Published
Dec 02, 2020
Tracked Since
Feb 18, 2026