Medium severity6.1NVD Advisory· Published Nov 25, 2020· Updated Jun 17, 2026
CVE-2020-29072
CVE-2020-29072
Description
A Cross-Site Script Inclusion vulnerability was found on LiquidFiles before 3.3.19. This client-side attack requires user interaction (opening a link) and successful exploitation could lead to encrypted e-mail content leakage via messages/sent?format=js and popup?format=js.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:liquidfiles:liquidfiles:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:liquidfiles:liquidfiles:*:*:*:*:*:*:*:*range: <3.3.19
- (no CPE)range: <3.3.19
- LiquidFiles/LiquidFilesdescription
Patches
Vulnerability mechanics
References
2- lean0x2f.github.io/liquidfiles_advisorynvdExploitThird Party Advisory
- man.liquidfiles.com/release_notes/version_3-3-x.htmlnvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.