MEDIUM 6.1 Go

SFTPGo WebClient vulnerable to Cross-site Scripting

GHSA-cf7g-cm7q-rq7f · CVE-2022-39220 · GO-2022-1015

Published · Modified

Description

Impact

Cross-site scripting (XSS) vulnerabilities have been reported to affect SFTPGo WebClient. If exploited, this vulnerability allows remote attackers to inject malicious code.

Patches

Fixed in v2.3.5.

Ready to move

Start Securing

Free, no credit card | First findings in minutes