CVE-2019-12769

SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functionality via ?Command=Upload with the Dir and File parameters.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:solarwinds:serv-u_managed_file_transfer:*:*:*:*:*:*:*:*
cpe:2.3:a:solarwinds:serv-u_managed_file_transfer:15.1.6:-:*:*:*:*:*:*

History

21 Nov 2024, 04:23

Type Values Removed Values Added
References () https://medium.com/%40clod81/cve-2019-12769-solarwinds-serv-u-managed-file-transfer-mft-web-client-15-1-6-a2dab98d668d - () https://medium.com/%40clod81/cve-2019-12769-solarwinds-serv-u-managed-file-transfer-mft-web-client-15-1-6-a2dab98d668d -
References () https://support.solarwinds.com/SuccessCenter/s/article/Serv-U-15-1-6-HotFix-2 - Release Notes, Vendor Advisory () https://support.solarwinds.com/SuccessCenter/s/article/Serv-U-15-1-6-HotFix-2 - Release Notes, Vendor Advisory

07 Nov 2023, 03:03

Type Values Removed Values Added
References
  • {'url': 'https://medium.com/@clod81/cve-2019-12769-solarwinds-serv-u-managed-file-transfer-mft-web-client-15-1-6-a2dab98d668d', 'name': 'https://medium.com/@clod81/cve-2019-12769-solarwinds-serv-u-managed-file-transfer-mft-web-client-15-1-6-a2dab98d668d', 'tags': ['Exploit', 'Third Party Advisory'], 'refsource': 'MISC'}
  • () https://medium.com/%40clod81/cve-2019-12769-solarwinds-serv-u-managed-file-transfer-mft-web-client-15-1-6-a2dab98d668d -

Information

Published : 2020-03-18 19:15

Updated : 2024-11-21 04:23


NVD link : CVE-2019-12769

Mitre link : CVE-2019-12769

CVE.ORG link : CVE-2019-12769


JSON object : View

Products Affected

solarwinds

  • serv-u_managed_file_transfer
CWE
CWE-352

Cross-Site Request Forgery (CSRF)