XSS Vulnerabilities in WebClient
CVE-2022-39220

6.1MEDIUM

Key Information:

Vendor

Drakkan

Status
Vendor
CVE Published:
20 September 2022

What is CVE-2022-39220?

SFTPGo is an SFTP server written in Go. Versions prior to 2.3.5 are subject to Cross-site scripting (XSS) vulnerabilities in the SFTPGo WebClient, allowing remote attackers to inject malicious code. This issue is patched in version 2.3.5. No known workarounds exist.

Affected Version(s)

sftpgo < 2.3.5

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-39220 : XSS Vulnerabilities in WebClient