MEDIUM 6.1 Go
SFTPGo WebClient vulnerable to Cross-site Scripting
GHSA-cf7g-cm7q-rq7f · CVE-2022-39220 · GO-2022-1015
Published · Modified
Description
Impact
Cross-site scripting (XSS) vulnerabilities have been reported to affect SFTPGo WebClient. If exploited, this vulnerability allows remote attackers to inject malicious code.
Patches
Fixed in v2.3.5.
Ready to move
Start Securing
Free, no credit card | First findings in minutes