WS_FTP Server Stored Cross-Site Scripting Vulnerability
CVE-2023-40047

8.3HIGH

Key Information:

Vendor
CVE Published:
27 September 2023

Summary

A stored cross-site scripting (XSS) vulnerability affecting WS_FTP Server versions prior to 8.8.2 allows attackers with administrative access to import SSL certificates containing malicious attributes. This XSS payload can be stored in the server's Management module. Once successfully executed by an administrator, attackers can run malicious JavaScript in the context of the victim's browser, leading to unauthorized actions or data compromise.

Affected Version(s)

WS_FTP Server 8.8.0

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Cristian Mocanu - Deloitte
.