First published: Tue Sep 20 2022(Updated: )
SFTPGo is an SFTP server written in Go. Versions prior to 2.3.5 are subject to Cross-site scripting (XSS) vulnerabilities in the SFTPGo WebClient, allowing remote attackers to inject malicious code. This issue is patched in version 2.3.5. No known workarounds exist.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sftpgo Project Sftpgo | <2.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-39220.
The severity of CVE-2022-39220 is medium with a severity value of 6.1.
Versions prior to 2.3.5 of SFTPGo are affected by CVE-2022-39220.
Remote attackers can exploit CVE-2022-39220 by injecting malicious code through Cross-site scripting (XSS) vulnerabilities in the SFTPGo WebClient.
To fix CVE-2022-39220, update SFTPGo to version 2.3.5 or later.