{"id":"CVE-2020-9447","details":"There is an XSS (cross-site scripting) vulnerability in GwtUpload 1.0.3 in the file upload functionality. Someone can upload a file with a malicious filename, which contains JavaScript code, which would result in XSS. Cross-site scripting enables attackers to steal data, change the appearance of a website, and perform other malicious activities like phishing or drive-by hacking.","aliases":["GHSA-5chj-xprr-7qqx"],"modified":"2026-07-08T17:57:10.485435Z","published":"2020-02-28T16:15:11.087Z","references":[{"type":"REPORT","url":"https://github.com/manolo/gwtupload/issues/32"},{"type":"EVIDENCE","url":"https://www.coresecurity.com/advisories/gwtupload-xss-file-upload-functionality"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/manolo/gwtupload","events":[{"introduced":"6422caed2c0550c158a2ab3f9ad7839646e1d713"},{"last_affected":"6422caed2c0550c158a2ab3f9ad7839646e1d713"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:gwtupload_project:gwtupload:1.0.3:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.0.3"},{"last_affected":"1.0.3"}]}}],"versions":["1.0.3","gwtupload-project-1.0.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-9447.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}