CVE-2020-27735: XSS
Published Jan 20, 2021
·Updated
An XSS issue was discovered in Wing FTP 6.4.4. An arbitrary IFRAME element can be included in the help pages via a crafted link, leading to the execution of (sandboxed) arbitrary HTML and JavaScript in the user's browser.
Affected Software
1 affected component
Wftpserver Wing Ftp Server=6.4.4
Event History
Jan 20, 2021
CVE Published
via MITRE·10:56 PM
Data Sourced
via MITRE·10:56 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-27735?
The severity of CVE-2020-27735 is medium with a CVSS score of 6.1.
2
What is the affected software for CVE-2020-27735?
The affected software for CVE-2020-27735 is Wing FTP Server 6.4.4.
3
What is the CWE for CVE-2020-27735?
The CWE for CVE-2020-27735 is CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
4
How can the XSS issue in Wing FTP 6.4.4 be exploited?
The XSS issue in Wing FTP 6.4.4 can be exploited by including an arbitrary IFRAME element in the help pages via a crafted link.
5
How can I fix the XSS issue in Wing FTP 6.4.4?
To fix the XSS issue in Wing FTP 6.4.4, it is recommended to update to a version that includes a patch for the vulnerability.