gotify/server vulnerable to Cross-site Scripting in the application image file upload in github.com/gotify/server