In WS_FTP Server versions before 8.8.5, reflected cross-site scripting issues have been identified on various user supplied inputs on the WS_FTP Server administrative interface.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://www.progress.com/ws_ftp | product |
https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-February-2024 | vendor advisory |