HTML and SMTP injections In LiquidFiles

Discovered by Youssef Taleb on behalf of The Missing Link Security

Vulnerability Details

HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform more advanced phishing attacks against an organisation.

Affected Versions

Discovered in: <= 3.7.13

Fixed Versions

Fixed in: 3.7.14

