PT-2023-6098 · Ipswitch · Ws Ftp Server

Published

2023-09-27

·

Updated

2023-09-28

·

CVE-2023-40047

CVSS v3.1

8.3

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WS FTP Server versions 8.8.0 through 8.8.1
Description A stored cross-site scripting (XSS) vulnerability exists in WS FTP Server's Management module. This issue is related to the handling of SSL certificate parameters. An attacker with administrative privileges could import a SSL certificate with malicious attributes containing cross-site scripting payloads, which could then be used to target WS FTP Server admins with a specialized payload. This payload results in the execution of malicious JavaScript within the context of the victim's browser.
Recommendations For WS FTP Server versions 8.8.0 through 8.8.1, update to version 8.8.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the Management module to minimize the risk of exploitation. Avoid importing SSL certificates with unknown or untrusted attributes until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-06801
CVE-2023-40047

Affected Products

Ws Ftp Server