[Bug 1158203] New: VUL-0: CVE-2016-1000037: pagure: XSS in file attachment endpoint