
Unauthenticated Access to Uploaded Files
Stored XSS via Malicious File Upload in machpanel 8.0.32.
Navigate to https://controlpaneldomain/Client/SubmitTicket.aspx and Upload PDF file that contain XSS scripts in metadata, after submitting the ticket you can execute malicius XSS script by accessing the uplaoded file.