CVE-2022-39220: XSS Vulnerabilities in WebClient
Published Sep 20, 2022
·Updated
SFTPGo is an SFTP server written in Go. Versions prior to 2.3.5 are subject to Cross-site scripting (XSS) vulnerabilities in the SFTPGo WebClient, allowing remote attackers to inject malicious code. This issue is patched in version 2.3.5. No known workarounds exist.
Affected Software
1 affected component
Sftpgo Project Sftpgo<2.3.5
Event History
Sep 20, 2022
CVE Published
via MITRE·10:10 PM
Data Sourced
via MITRE·10:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2022-39220.
2
What is the severity of CVE-2022-39220?
The severity of CVE-2022-39220 is medium with a severity value of 6.1.
3
What software versions are affected by CVE-2022-39220?
Versions prior to 2.3.5 of SFTPGo are affected by CVE-2022-39220.
4
How can remote attackers exploit CVE-2022-39220?
Remote attackers can exploit CVE-2022-39220 by injecting malicious code through Cross-site scripting (XSS) vulnerabilities in the SFTPGo WebClient.
5
How can I fix CVE-2022-39220?
To fix CVE-2022-39220, update SFTPGo to version 2.3.5 or later.