PT-2019-15822 · Maxum · Rumpus Ftp Web File Manager

Published

2019-12-16

·

Updated

2019-12-23

·

CVE-2019-19368

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Rumpus FTP Web File Manager version 8.2.9.1
Description A Reflected Cross Site Scripting issue was found in the Login page, allowing an attacker to execute arbitrary Javascripts by sending a crafted link to end users.
Recommendations For Rumpus FTP Web File Manager version 8.2.9.1, consider disabling the Login page functionality until a patch is available to prevent exploitation of the Reflected Cross Site Scripting issue.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19368

Affected Products

Rumpus Ftp Web File Manager