One Click, No File: Upload XSS Without the Upload
TL;DR
Reflected XSS on a file upload endpoint is routinely written off as unexploitable. The reasoning is always the same: the victim would have to craft a malicious file and upload it themselves, so
blog.cain.tech13 min read