Junglewise Threat Intelligence

CVE-2026-41877: R-SOFT DMS stored XSS in file upload functionality

CVE-2026-41877 · Severity: info · CVSS 5.1 · Published 2026-07-10

Technologies: R-SOFT SERWIS DMS. Vendors: R-SOFT SERWIS.

Executive brief

R-SOFT DMS, a document management system, contains a security flaw in its file upload feature. An authorized user can upload a file with a malicious name containing computer code. When other users or administrators view the file list, this code automatically runs in their browser, potentially allowing the attacker to steal session information or perform actions on behalf of other users.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in R-SOFT DMS within the file upload module. The application fails to properly sanitize the filename parameter before storing it and subsequently rendering it in the web interface. An authenticated attacker can upload a file with a crafted name containing a JavaScript payload. This payload executes in the context of any user who views the file list or upload status pages. The vulnerability is addressed in versions v3.19-2832 and v3.17-2580.

Affected products

  • R-SOFT SERWIS DMS versions before v3.19-2832 and v3.17-2580

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References

Related threats