PT-2017-16416 · Biscom · Biscom Secure File Transfer
Published
2017-06-28
·
Updated
2020-02-20
·
CVE-2017-5241
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Biscom Secure File Transfer versions 5.0.0.0 through 5.1.1024
Description
The issue concerns post-authentication persistent cross-site scripting (XSS) in specific fields, including the
Name and Description fields of a Workspace, as well as the Description field of a File Details pane of a file stored in a Workspace.Recommendations
For versions 5.0.0.0 through 5.1.1024, update to version 5.1.1025 to resolve the issue.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Biscom Secure File Transfer