Search
Total
3 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2020-5194 | 1 Cerberusftp | 1 Ftp Server | 2021-07-21 | 5.5 MEDIUM | 5.4 MEDIUM |
| The zip API endpoint in Cerberus FTP Server 8 allows an authenticated attacker without zip permission to use the zip functionality via an unrestricted API endpoint. Improper permission verification occurs when calling the file/ajax_download_zip/zip_name endpoint. The result is that a user without permissions can zip and download files even if they do not have permission to view whether the file exists. | |||||
| CVE-2019-25046 | 1 Cerberusftp | 1 Ftp Server | 2021-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document. | |||||
| CVE-2020-5195 | 1 Cerberusftp | 1 Ftp Server | 2020-01-22 | 4.3 MEDIUM | 6.1 MEDIUM |
| Reflected XSS through an IMG element in Cerberus FTP Server prior to versions 11.0.1 and 10.0.17 allows a remote attacker to execute arbitrary JavaScript or HTML via a crafted public folder URL. This occurs because of the folder_up.png IMG element not properly sanitizing user-inserted directory paths. The path modification must be done on a publicly shared folder for a remote attacker to insert arbitrary JavaScript or HTML. The vulnerability impacts anyone who clicks the malicious link crafted by the attacker. | |||||
