SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/161400/SolarWinds-Serv-U-FTP-Server-15.2.1-Cross-Site-Scripting.html | Exploit Third Party Advisory VDB Entry |
http://seclists.org/fulldisclosure/2021/Feb/37 | Exploit Mailing List Third Party Advisory |
https://documentation.solarwinds.com/en/success_center/servu/Content/Release_Notes/Servu_15-2-2_release_notes.htm | Release Notes Vendor Advisory |
https://www.themissinglink.com.au/security-advisories-cve-2020-28001 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2021-02-03T15:53:33
Updated: 2021-02-12T18:06:15
Reserved: 2020-10-30T00:00:00
Link: CVE-2020-28001
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-02-03T16:15:13.353
Modified: 2021-02-25T15:18:23.957
Link: CVE-2020-28001
JSON object: View
Redhat Information
No data.
CWE