CVE-2019-12769: CSRF
SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functionality via ?Command=Upload with the Dir and File parameters.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12769?
CVE-2019-12769 is a vulnerability in SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 that is vulnerable to Cross-Site Request Forgery in the file upload functionality.
How severe is CVE-2019-12769?
CVE-2019-12769 has a severity keyword level of high with a severity value of 8.8.
What software versions are affected by CVE-2019-12769?
Versions up to and including 15.1.5 and version 15.1.6 of SolarWinds Serv-U Managed File Transfer are affected by CVE-2019-12769.
Is there a reference for CVE-2019-12769?
References for CVE-2019-12769 can be found at the provided links: https://medium.com/@clod81/cve-2019-12769-solarwinds-serv-u-managed-file-transfer-mft-web-client-15-1-6-a2dab98d668d and https://support.solarwinds.com/SuccessCenter/s/article/Serv-U-15-1-6-HotFix-2.
How can I fix CVE-2019-12769?
To address CVE-2019-12769, it is recommended to apply the necessary security updates, such as Hotfix 2 for version 15.1.6 of SolarWinds Serv-U Managed File Transfer.