CVE-2019-12769
HIGHSolarWinds Serv-U Managed File Transfer < 15.1.6 Hotfix 2 - Cross-Site Request Forgery via File Upload
Title source: llmDescription
SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functionality via ?Command=Upload with the Dir and File parameters.
References (2)
Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://support.solarwinds.com/SuccessCenter/s/article/Serv-U-15-1-6-HotFix-2
Various Sources x_refsource_misc
https://medium.com/%40clod81/cve-2019-12769-solarwinds-serv-u-managed-file-transfer-mft-web-client-15-1-6-a2dab98d668d
Scores
CVSS v3
8.8
EPSS
0.0063
EPSS Percentile
70.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-352
Status
published
Products (2)
solarwinds/serv-u_managed_file_transfer
15.1.6
solarwinds/serv-u_managed_file_transfer
< 15.1.5
Published
Mar 18, 2020
Tracked Since
Feb 18, 2026