SFTPGo WebClient vulnerable to Cross-site Scripting
Description
Published to the GitHub Advisory Database
Sep 20, 2022
Reviewed
Sep 20, 2022
Published by the National Vulnerability Database
Sep 20, 2022
Last updated
Jan 31, 2023
Impact
Cross-site scripting (XSS) vulnerabilities have been reported to affect SFTPGo WebClient. If exploited, this vulnerability allows remote attackers to inject malicious code.
Patches
Fixed in v2.3.5.
References