vendor:
Cerberus FTP Server
by:
Mohammad Hossein Kaviyany
6.1
CVSS
MEDIUM
Stored XSS
79
CWE
Product Name: Cerberus FTP Server
Affected Version From: 11.0 releases prior to 11.0.4, 10.0 releases prior to 10.0.19, 9.0 and earlier
Affected Version To: 11.0 releases prior to 11.0.4, 10.0 releases prior to 10.0.19, 9.0 and earlier
Patch Exists: YES
Related CWE: CVE-2019-25046
CPE: a:cerberus_ftp_server:cerberus_ftp_server:11.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows Server 2016
2021
Cerberus FTP web Service 11 – ‘svg’ Stored Cross-Site Scripting (XSS)
This stored XSS bug happens when a user uploads an svg file with the following content: <svg onload="alert(123)"/>. Exploit POC: Vulnerable Path: /file/upload, Parameter: files (POST), Vector: <svg onload="alert(123)"/>.
Mitigation:
Upgrade to Cerberus FTP Server version 11.0.4, 10.0.19, or later.