Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functionality. A low privileged user will be able to share a file with an admin user, which could lead to privilege escalation.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/HFO4/cloudreve(Go) | 1.0.0 | N/A | N/A |
| github.com/cloudreve/Cloudreve/v3(Go) | 3.0.0 | 3.6.0-beta1 | N/A |
CVSS Metrics