Vulnerabilities (CVE)

Filtered by vendor Cerberusftp Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-5194 1 Cerberusftp 1 Ftp Server 2021-07-21 5.5 MEDIUM 5.4 MEDIUM
The zip API endpoint in Cerberus FTP Server 8 allows an authenticated attacker without zip permission to use the zip functionality via an unrestricted API endpoint. Improper permission verification occurs when calling the file/ajax_download_zip/zip_name endpoint. The result is that a user without permissions can zip and download files even if they do not have permission to view whether the file exists.
CVE-2019-25046 1 Cerberusftp 1 Ftp Server 2021-06-17 4.3 MEDIUM 6.1 MEDIUM
The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document.
CVE-2020-5195 1 Cerberusftp 1 Ftp Server 2020-01-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS through an IMG element in Cerberus FTP Server prior to versions 11.0.1 and 10.0.17 allows a remote attacker to execute arbitrary JavaScript or HTML via a crafted public folder URL. This occurs because of the folder_up.png IMG element not properly sanitizing user-inserted directory paths. The path modification must be done on a publicly shared folder for a remote attacker to insert arbitrary JavaScript or HTML. The vulnerability impacts anyone who clicks the malicious link crafted by the attacker.