SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functionality via ?Command=Upload with the Dir and File parameters.
References
Configurations
Configuration 1 (hide)
|
History
07 Nov 2023, 03:03
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2020-03-18 19:15
Updated : 2023-11-07 03:03
NVD link : CVE-2019-12769
Mitre link : CVE-2019-12769
JSON object : View
Products Affected
solarwinds
- serv-u_managed_file_transfer
CWE
CWE-352
Cross-Site Request Forgery (CSRF)