vendor:
HTTP Commander
by:
Oscar Sandén
8.8
CVSS
HIGH
Stored Cross Site Scripting (XSS)
79
CWE
Product Name: HTTP Commander
Affected Version From: 3.1.2009
Affected Version To: 3.1.2009
Patch Exists: Yes
Related CWE: CVE-2022-12345
CPE: a:element-it:http_commander:3.1.9
Platforms Tested: Windows Server 2016
2022
HTTP Commander 3.1.9 – Stored Cross Site Scripting (XSS)
There is a stored XSS in the 'Zip content' feature of the HTTP commander application. The vulnerable field is the filename of the files inside the zip. This vulnerability exists in 3.x of the HTTP commander application.
Mitigation:
Upgrade to the latest version of HTTP Commander.