Executive brief
R-SOFT DMS, a document management system, contains a security flaw in its file upload feature. An authorized user can upload a file with a malicious name containing computer code. When other users or administrators view the file list, this code automatically runs in their browser, potentially allowing the attacker to steal session information or perform actions on behalf of other users.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in R-SOFT DMS within the file upload module. The application fails to properly sanitize the filename parameter before storing it and subsequently rendering it in the web interface. An authenticated attacker can upload a file with a crafted name containing a JavaScript payload. This payload executes in the context of any user who views the file list or upload status pages. The vulnerability is addressed in versions v3.19-2832 and v3.17-2580.
Affected products
- R-SOFT SERWIS DMS versions before v3.19-2832 and v3.17-2580
Timeline
- 2026-07-10: disclosed
- 2026-07-10: advisory