CVE-2017-6803

HIGH

SolarWinds FTP Voyager 16.2.0 - CSRF

Title source: llm

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 allow remote attackers to hijack the authentication of users for requests that (1) change the admin password, (2) terminate the scheduler, or (3) possibly execute arbitrary commands via crafted requests to Admin/XML/Result.xml.

Exploits (1)

exploitdb WORKING POC VERIFIED
by hyp3rlinx · htmlwebappsxml
https://www.exploit-db.com/exploits/41574

Scores

CVSS v3 8.8
EPSS 0.0018
EPSS Percentile 39.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
solarwinds/ftp_voyager 16.2.0
Published Mar 20, 2017
Tracked Since Feb 18, 2026