When a low privileged user uploads images in the report section, the filenames are not properly sanitized; this potentially enables stored XSS attacks.
↧