Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cf7g-cm7q-rq7f

Опубликовано: 20 сент. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

SFTPGo WebClient vulnerable to Cross-site Scripting

Impact

Cross-site scripting (XSS) vulnerabilities have been reported to affect SFTPGo WebClient. If exploited, this vulnerability allows remote attackers to inject malicious code.

Patches

Fixed in v2.3.5.

Пакеты

Наименование

github.com/drakkan/sftpgo

go
Затронутые версииВерсия исправления

< 2.3.5

2.3.5

EPSS

Процентиль: 39%
0.00176
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 3 лет назад

SFTPGo is an SFTP server written in Go. Versions prior to 2.3.5 are subject to Cross-site scripting (XSS) vulnerabilities in the SFTPGo WebClient, allowing remote attackers to inject malicious code. This issue is patched in version 2.3.5. No known workarounds exist.

CVSS3: 6.1
debian
больше 3 лет назад

SFTPGo is an SFTP server written in Go. Versions prior to 2.3.5 are su ...

EPSS

Процентиль: 39%
0.00176
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79