PT-2019-17687 · Unknown · Http File Server

CVE-2019-5458

·

Publicado

2019-07-30

·

Atualizado

2023-01-31

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions http-file-server (all versions)
Description A cross-site scripting (XSS) issue allows an attacker with access to the server file system to execute arbitrary JavaScript code in a victim's browser. The package fails to sanitize filenames, enabling attackers to execute arbitrary JavaScript in the victim's browser through files with names containing malicious code.
Recommendations For all versions, consider using an alternative package until a fix is made available. As a temporary workaround, consider restricting access to files with potentially malicious names to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-5458
GHSA-7J93-2H6R-HM49

Produtos afetados

Http File Server