CVE-2021-3395
A cross-site scripting (XSS) vulnerability in Pryaniki 6.44.3 allows remote authenticated users to upload an arbitrary file. The JavaScript code will execute when someone visits the attachment.
Date published : 2021-02-02
https://github.com/jet-pentest/CVE-2021-3395/