Problem Summary: Security vulnerabilities when uploading an HTML file in the system.
We currently can upload an HTML file as an attachment from the Personal Details\Additional Information\Marital Status screen. Our Security group has brought to our attention that these files can be embedded with JavaScript, presenting a security vulnerability. Please see the following questions below:
- Are there potential risks to the system when uploading an HTML file?
- Are there any known issues with uploading this file type into the system?
- Does the software validate for any embedded scripting?