A cross-site scripting (XSS) vulnerability in Pryaniki 6.44.3 allows remote authenticated users to upload an arbitrary file. The JavaScript code will execute when someone visits the attachment.Referenceshttps://github.com/jet-pentest/CVE-2021-3395/https://pryaniky.com/en/home/