CVE-2019-25046

MEDIUM

Cerberus FTP Server <10.0.19, <11.0.4 - XSS

Title source: llm

Description

The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document.

Exploits (1)

exploitdb WORKING POC
by Mohammad Hossein Kaviyany · textwebappsmultiple
https://www.exploit-db.com/exploits/49981

Scores

CVSS v3 6.1
EPSS 0.0042
EPSS Percentile 61.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
cerberusftp/ftp_server < 10.0.19
Published Jun 10, 2021
Tracked Since Feb 18, 2026