The vulnerability exists due to a missing output encoding call within the Word export component. The application fails to properly sanitize the filename of uploaded image attachments. This flaw allows an authenticated user to inject arbitrary HTML payloads into an image tag's alternative text attribute, leading to Stored Cross-Site Scripting (XSS) when another user exports or views the affected bug tracking page.
Published: 2026-07-23
Base Score: 3.5
Vector: CVSS2#AV:N/AC:M/Au:S/C:N/I:P/A:N
Severity: Low
Base Score: 5.4
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Severity: Medium
Base Score: 8.6
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Severity: High