In NCH Quorum v2.03 and earlier, XSS exists via /uploaddoc?id= (reflected).

By admin