GHSA-wpg4-f3mj-hxh3Medium

OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can...

Published
August 17, 2026
Last Modified
August 17, 2026

🔗 CVE IDs covered (1)

📋 Description

OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be exploited by a low-privileged attacker via the upload of a file with a malicious filename containing JavaScript code. The vulnerability exists in all locations where a file can be attached and prepared for upload to the server.

This issue was fixed in OutSystems Service Center version 11.41.2

🔗 References (5)