MEDIUM
Phraseanet
CVE published 2026-02-11
CVE-2018-25157
CVE-2018-25157 is a stored cross-site scripting vulnerability in Phraseanet 4.0.3 that allows authenticated users to inject malicious scripts through crafted file names during document uploads. This vulnerability can lead to potential cookie theft or user redirection when the file is viewed. Defenders responsible for Phraseanet installations should assess exposure and prioritize remediation to prevent pot [truncated]