FileBrowser Vulnerable to Stored XSS via SVG File in Public Share (Missing CSP Header)
FileBrowser Quantum serves inline SVG files without a Content-Security-Policy header, allowing embedded JavaScript in SVG files to execute when accessed via public share links. Verified on v1.3.0-stable.