This is most likely exploitable with malicious sub files.
Attach a file by drag & drop or click to upload