- Status Closed
-
Assigned To
cbay - Private
Opened by malko - 09.10.2026
Last edited by cbay - 09.10.2026
FS#523 - Stored Cross-Site Scripting (XSS) via File Upload / PDF Rendering
Affected endpoint: `https://security.alwaysdata.com/?getfile=290`
Vulnerability type: Cross-Site Scripting (XSS)
Status: Requires confirmation of application-origin execution
Severity: To be determined based on the execution context and affected users
## Summary
A potentially unsafe file-upload and file-rendering behavior was identified on the application. A test PDF, `test-xss.pdf`, was uploaded and accessed through the application's file retrieval endpoint.
When the PDF was opened, a browser notification displaying “XSS Tested Successfully” appeared, indicating that script-related behavior was triggered in the document-viewing workflow.
Further validation is required to determine whether the behavior constitutes stored XSS in the application's security origin or JavaScript execution isolated to the PDF viewer.
## Steps to Reproduce
1. Upload a PDF containing a benign JavaScript execution test through the application's file-upload functionality.
2. Open the uploaded file using the application's file retrieval endpoint.
3. Observe the PDF viewer and check whether the test notification appears.
4. If authorized, verify the execution origin and whether the same behavior affects another user who opens the uploaded file.
## Observed Result
A browser notification displaying “XSS Tested Successfully” appeared while the PDF was open in the browser.
## Expected Result
Uploaded files should be served and rendered safely. Untrusted document content must not execute script with privileges belonging to the application's origin.
## Security Impact
If the uploaded document can execute JavaScript in the application's origin when opened by another user, an attacker might be able to perform actions within that user's authenticated session, subject to the application's security controls.
If execution is confined to a sandboxed PDF viewer or a separate origin, the impact may be substantially lower.
## Recommendations
* Serve untrusted uploads from a separate, appropriately isolated origin.
* Apply strict file-type validation and safe content-disposition headers.
* Configure an appropriate Content Security Policy where applicable.
* Ensure PDF rendering and JavaScript execution follow the viewer's security model.
* Test uploaded files with a current, securely configured PDF viewer.
* Verify that other users cannot be affected through the same upload-and-view workflow.
## Evidence
The supplied screenshot shows the notification “XSS Tested Successfully” while viewing `test-xss.pdf` through the application's file endpoint.
Loading...
Available keyboard shortcuts
- Alt + ⇧ Shift + l Login Dialog / Logout
- Alt + ⇧ Shift + a Add new task
- Alt + ⇧ Shift + m My searches
- Alt + ⇧ Shift + t focus taskid search
Tasklist
- o open selected task
- j move cursor down
- k move cursor up
Task Details
- n Next task
- p Previous task
- Alt + ⇧ Shift + e ↵ Enter Edit this task
- Alt + ⇧ Shift + w watch task
- Alt + ⇧ Shift + y Close Task
Task Editing
- Alt + ⇧ Shift + s save task
store xss alwaysdata.png
store xss alwaysdata1.txt
Hello,
We're running the latest Flyspray version (1.0-rc11) so you should report it to them.
Kind regards,
Cyril