[Bug 1158203] VUL-0: CVE-2016-1000037: pagure: XSS in file attachment endpoint