PT-2017-16416 · Biscom · Biscom Secure File Transfer

Published

2017-06-28

·

Updated

2020-02-20

·

CVE-2017-5241

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Biscom Secure File Transfer versions 5.0.0.0 through 5.1.1024
Description The issue concerns post-authentication persistent cross-site scripting (XSS) in specific fields, including the Name and Description fields of a Workspace, as well as the Description field of a File Details pane of a file stored in a Workspace.
Recommendations For versions 5.0.0.0 through 5.1.1024, update to version 5.1.1025 to resolve the issue.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-5241

Affected Products

Biscom Secure File Transfer