WS_FTP Server Stored Cross-Site Scripting Vulnerability
CVE-2023-40047
8.3HIGH
Summary
A stored cross-site scripting (XSS) vulnerability affecting WS_FTP Server versions prior to 8.8.2 allows attackers with administrative access to import SSL certificates containing malicious attributes. This XSS payload can be stored in the server's Management module. Once successfully executed by an administrator, attackers can run malicious JavaScript in the context of the victim's browser, leading to unauthorized actions or data compromise.
Affected Version(s)
WS_FTP Server 8.8.0
References
CVSS V3.1
Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Cristian Mocanu - Deloitte