Описание
SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload.
Ссылки
- Not ApplicableThird Party Advisory
- Vendor Advisory
- Third Party Advisory
- Permissions RequiredThird Party Advisory
- Not ApplicableThird Party Advisory
- Vendor Advisory
- Third Party Advisory
- Permissions RequiredThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:solarwinds:serv-u_ftp_server:15.1:*:*:*:*:*:*:*
cpe:2.3:a:solarwinds:serv-u_mft_server:15.1:*:*:*:*:*:*:*
EPSS
Процентиль: 77%
0.01049
Низкий
4.8 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
больше 3 лет назад
SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload.
EPSS
Процентиль: 77%
0.01049
Низкий
4.8 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79