CVE-2023-40047

CVSS V2 None CVSS V3 None
Description
In WS_FTP Server version prior to 8.8.2, a stored cross-site scripting (XSS) vulnerability exists in WS_FTP Server's Management module. An attacker with administrative privileges could import a SSL certificate with malicious attributes containing cross-site scripting payloads.  Once the cross-site scripting payload is successfully stored,  an attacker could leverage this vulnerability to target WS_FTP Server admins with a specialized payload which results in the execution of malicious JavaScript within the context of the victims browser.
Overview
  • CVE ID
  • CVE-2023-40047
  • Assigner
  • ProgressSoftware
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-09-27T14:50:55.329Z
  • Last Modified Date
  • 2023-09-27T15:23:44.201Z
History
Created Old Value New Value Data Type Notes
2024-06-25 02:26:57 Added to TrackCVE