Reflected Cross-Site Scripting Vulnerabilities in WS_FTP Server Administrative Interface
CVE-2024-1474

6.1MEDIUM

Key Information:

Vendor
CVE Published:
21 February 2024

Summary

A reflected cross-site scripting vulnerability has been identified in WS_FTP Server before version 8.8.5. This vulnerability arises from insufficient validation of user-supplied inputs within the administrative interface, allowing attackers to inject malicious scripts. Users interacting with the affected components may inadvertently expose their systems to potential exploits if they interact with crafted links. It is crucial for organizations utilizing WS_FTP Server to apply the latest updates and security patches to mitigate these risks.

Affected Version(s)

WS_FTP Server 8.8.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

BugCrowd - mert
BugCrowd - isira_adithya
.