SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functionality via ?Command=Upload with the Dir and File parameters.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:23
Type | Values Removed | Values Added |
---|---|---|
References | () https://medium.com/%40clod81/cve-2019-12769-solarwinds-serv-u-managed-file-transfer-mft-web-client-15-1-6-a2dab98d668d - | |
References | () https://support.solarwinds.com/SuccessCenter/s/article/Serv-U-15-1-6-HotFix-2 - Release Notes, Vendor Advisory |
07 Nov 2023, 03:03
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2020-03-18 19:15
Updated : 2024-11-21 04:23
NVD link : CVE-2019-12769
Mitre link : CVE-2019-12769
CVE.ORG link : CVE-2019-12769
JSON object : View
Products Affected
solarwinds
- serv-u_managed_file_transfer
CWE
CWE-352
Cross-Site Request Forgery (CSRF)