nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25046 CVE-2019-25046
MEDIUM
Cerberus FTP Web Service 11 - 'svg' Stored Cross-Site Scripting (XSS)
Record summary
CVE-2019-25046 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCerberus FTP Web Service 11 - 'svg' Stored Cross-Site Scripting (XSS)ExploitDB exploitby Mohammad Hossein KaviyanyNot analyzed1 file
References
3cerberusftp.com
https://www.cerberusftp.com/products/releasenotes cerberusftp.com
https://www.cerberusftp.com/xss-vulnerability-when-previewing-svg-content