Discovered by Edward Prior on behalf of The Missing Link Security
The application was found to be vulnerable to an authenticated Stored Cross-Site Scripting (XSS) vulnerability in the upload and download functionality. Which could be leveraged to escalate privileges or compromise any accounts they can coerce into observing the targeted files.
Discovered in: 19.0
Fixed In: 19.0 minor release