PT-2022-24820 · Sftpgo · Sftpgo

Drakkan

·

Published

2022-09-20

·

Updated

2024-08-21

·

CVE-2022-39220

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SFTPGo versions prior to 2.3.5
Description SFTPGo is an SFTP server written in Go. The SFTPGo WebClient is subject to Cross-site scripting (XSS) vulnerabilities, allowing remote attackers to inject malicious code. This issue is patched in version 2.3.5. No known workarounds exist.
Recommendations For versions prior to 2.3.5, update to version 2.3.5 to resolve the issue. As a temporary workaround, consider restricting access to the SFTPGo WebClient until the update is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-39220
GHSA-CF7G-CM7Q-RQ7F
GO-2022-1015

Affected Products

Sftpgo