CVE-2015-7676: XSS
Published Apr 15, 2016
·Updated
Ipswitch MOVEit File Transfer (formerly DMZ) 8.1 and earlier, when configured to support file view on download, allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading HTML files.
Affected Software
1 affected component
IPSwitch MOVEit DMZ<=8.1
Event History
Apr 15, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7676?
CVE-2015-7676 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-7676?
To fix CVE-2015-7676, upgrade to a version of Ipswitch MOVEit File Transfer later than 8.1.
3
Who is affected by CVE-2015-7676?
Users of Ipswitch MOVEit File Transfer up to version 8.1 are affected by CVE-2015-7676.
4
What type of vulnerability is CVE-2015-7676?
CVE-2015-7676 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2015-7676 be exploited remotely?
Yes, CVE-2015-7676 can be exploited by remote authenticated users.