Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-40047
HistorySep 27, 2023 - 3:18 p.m.

Cross site scripting

2023-09-2715:18:00
PRIOn knowledge base
www.prio-n.com
4
ws_ftp server
cross-site scripting
xss
ssl certificate
administrative privileges
malicious javascript
nvd

6 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.2%

In WS_FTP Server version prior to 8.8.2,Β a stored cross-site scripting (XSS) vulnerability exists in WS_FTP Server’s Management module. An attacker with administrative privileges could import a SSL certificate with malicious attributes containing cross-site scripting payloads.Β  Once the cross-site scripting payload is successfully stored,Β Β an attacker could leverage this vulnerability to target WS_FTP Server admins with a specialized payload which results in the execution of malicious JavaScript within the context of the victims browser.

CPENameOperatorVersion
ws_ftp_serverlt8.8.2

6 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.2%

Related for PRION:CVE-2023-40047