PT-2026-5837 · Unknown · Easy Transfer Wifi Transfer

Published

2026-02-03

·

Updated

2026-02-04

·

CVE-2020-37087

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Easy Transfer Wifi Transfer versions 1.7 for iOS
Description A persistent cross-site scripting issue exists in Easy Transfer Wifi Transfer version 1.7 for iOS. Remote attackers can inject malicious scripts by manipulating the oldPath, newPath, and path parameters in the Create Folder and Move/Edit functions. This is due to improper input validation when handling POST requests, allowing for the execution of arbitrary JavaScript within the mobile web application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-37087

Affected Products

Easy Transfer Wifi Transfer