← Back

Roastslav

roastslav

1 CVE • 1 product

Products (1)

Click to collapse
Toggle
Quickdrop
quickdrop

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Roastslav
1Quickdrop
Jun 17, 2026
Apr 7, 2026
5.3 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
QuickDrop is an easy-to-use file sharing application. Prior to 1.5.3, a stored XSS vulnerability exists in the file preview endpoint. The application allows SVG files to be uploaded via the /api/file/upload-chunk endpoin...Show more
QuickDrop is an easy-to-use file sharing application. Prior to 1.5.3, a stored XSS vulnerability exists in the file preview endpoint. The application allows SVG files to be uploaded via the /api/file/upload-chunk endpoint. An attacker can upload a specially crafted SVG file containing a JavaScript payload. When any user views the file preview, the script executes in the context of the application's domain. This vulnerability is fixed in 1.5.3.Show less