Skip to content

XSS Vulnerabilities in WebClient

Moderate
drakkan published GHSA-cf7g-cm7q-rq7f Sep 17, 2022

Package

gomod sftpgo (Go)

Affected versions

< v2.3.5

Patched versions

v2.3.5

Description

Impact

Cross-site scripting (XSS) vulnerabilities have been reported to affect SFTPGo WebClient. If exploited, this vulnerability allows remote attackers to inject malicious code.

Patches

Fixed in v2.3.5.

Severity

Moderate

CVE ID

CVE-2022-39220

Weaknesses

No CWEs