Vulnerability Description
An XSS issue was discovered in Wing FTP 6.4.4. An arbitrary IFRAME element can be included in the help pages via a crafted link, leading to the execution of (sandboxed) arbitrary HTML and JavaScript in the user's browser.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wftpserver | Wing Ftp Server | 6.4.4 |
Related Weaknesses (CWE)
References
- https://wshenk.blogspot.com/2021/01/xss-in-wing-ftps-web-interface-cve-2020.htmlExploitThird Party Advisory
- https://www.wftpserver.com/serverhistory.htmRelease NotesVendor Advisory
- https://wshenk.blogspot.com/2021/01/xss-in-wing-ftps-web-interface-cve-2020.htmlExploitThird Party Advisory
- https://www.wftpserver.com/serverhistory.htmRelease NotesVendor Advisory
FAQ
What is CVE-2020-27735?
CVE-2020-27735 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An XSS issue was discovered in Wing FTP 6.4.4. An arbitrary IFRAME element can be included in the help pages via a crafted link, leading to the execution of (sandboxed) arbitrary HTML and JavaScript i...
How severe is CVE-2020-27735?
CVE-2020-27735 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27735?
Check the references section above for vendor advisories and patch information. Affected products include: Wftpserver Wing Ftp Server.