Medium severity6.1NVD Advisory· Published Feb 28, 2020· Updated Jun 17, 2026
CVE-2020-9447
CVE-2020-9447
Description
There is an XSS (cross-site scripting) vulnerability in GwtUpload 1.0.3 in the file upload functionality. Someone can upload a file with a malicious filename, which contains JavaScript code, which would result in XSS. Cross-site scripting enables attackers to steal data, change the appearance of a website, and perform other malicious activities like phishing or drive-by hacking.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.googlecode.gwtupload:gwtuploadMaven | <= 1.0.3 | — |
Affected products
3- cpe:2.3:a:gwtupload_project:gwtupload:1.0.3:*:*:*:*:*:*:*
- GwtUpload/GwtUploaddescription
Patches
Vulnerability mechanics
References
4- github.com/manolo/gwtupload/issues/32nvdExploitIssue TrackingThird Party AdvisoryWEB
- www.coresecurity.com/advisories/gwtupload-xss-file-upload-functionalitynvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-5chj-xprr-7qqxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-9447ghsaADVISORY
News mentions
0No linked articles in our index yet.