VulnerabilityModified
CVE-2020-22428
SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload.
MEDIUM 4.8EPSS 1.18%
Does this matter?
Lower severity and a low EPSS score (1.18%). Track it; it rarely justifies an emergency change on its own.
Description
SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload.
- CVSS 3.1
- 4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.18% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- solarwinds/serv-u ftp server · solarwinds/serv-u mft server
- Source
- cve@mitre.org
References
- https://github.com/matrixNot Applicable, Third Party Advisory
- https://support.solarwinds.com/SuccessCenter/s/article/Serv-U-15-1-6-Hotfix-3?language=en_USVendor Advisory
- https://twitter.com/gm4tr1xThird Party Advisory
- https://www.linkedin.com/in/gabrielegristinaPermissions Required, Third Party Advisory
- https://github.com/matrixNot Applicable, Third Party Advisory
- https://support.solarwinds.com/SuccessCenter/s/article/Serv-U-15-1-6-Hotfix-3?language=en_USVendor Advisory
- https://twitter.com/gm4tr1xThird Party Advisory
- https://www.linkedin.com/in/gabrielegristinaPermissions Required, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.