SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functionality via ?Command=Upload with the Dir and File parameters.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2020-03-18 19:15
Updated : 2023-11-07 03:03
NVD link : CVE-2019-12769
Mitre link : CVE-2019-12769
CVE.ORG link : CVE-2019-12769
JSON object : View
Products Affected
solarwinds
- serv-u_managed_file_transfer
CWE
CWE-352
Cross-Site Request Forgery (CSRF)