Title: Multiple Reflected Cross-Site Scripting (XSS) on WS_fTP
CVE ID: CVE-2022-36967
CVSSv3 Base Score: 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Vendor: Progress
Products: WS_FTP Server
Advisory Release Date: 08-02-22
Advisory URL: https://labs.integrity.pt/advisories/CVE-2022-36967
Credits: Discovery by Guilherme Santos (rondons) <guilherme.santos[at]devoteam.com> & Caio Farias (g3n3) <caio.farias[at]devoteam.com>
In WS_FTP Server prior to version 8.7.3, multiple reflected cross-site scripting (XSS) vulnerabilities exist in WS_FTP Servers administrative web interface. It is possible for a remote attacker to inject arbitrary JavaScript in a WS_FTP administrators web session which would allow the attacker to execute code within the context of the victim’s browser.
© 2024 INTEGRITY S.A. All rights reserved. | Cookie Policy