{"api_version":"1","generated_at":"2026-07-23T15:10:43+00:00","cve":"CVE-2020-11704","urls":{"html":"https://cve.report/CVE-2020-11704","api":"https://cve.report/api/cve/CVE-2020-11704.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-11704","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-11704"},"summary":{"title":"CVE-2020-11704","description":"An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Web Interface has Multiple Stored and Reflected XSS. GetInheritedProperties is Reflected via the groups parameter. GetUserInfo is Reflected via POST data. SetUserInfo is Stored via the general parameter.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-04-12 03:15:00","updated_at":"2020-04-13 17:16:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://github.com/belong2yourself/vulnerabilities/tree/master/ProVide/Web%20Admin%20Interface%20-%20Multiple%20Cross-Site-Scripting","name":"https://github.com/belong2yourself/vulnerabilities/tree/master/ProVide/Web%20Admin%20Interface%20-%20Multiple%20Cross-Site-Scripting","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"vulnerabilities/ProVide/Web Admin Interface - Multiple Cross-Site-Scripting at master · belong2yourself/vulnerabilities · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.provideserver.com/security/","name":"https://www.provideserver.com/security/","refsource":"MISC","tags":["Vendor Advisory"],"title":"Secure cloud storage & file sharing | ProVide","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-11704","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-11704","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"11704","vulnerable":"1","versionEndIncluding":"13.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"provideserver","cpe5":"provide_ftp_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-11704","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Web Interface has Multiple Stored and Reflected XSS. GetInheritedProperties is Reflected via the groups parameter. GetUserInfo is Reflected via POST data. SetUserInfo is Stored via the general parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.provideserver.com/security/","refsource":"MISC","name":"https://www.provideserver.com/security/"},{"url":"https://github.com/belong2yourself/vulnerabilities/tree/master/ProVide/Web%20Admin%20Interface%20-%20Multiple%20Cross-Site-Scripting","refsource":"MISC","name":"https://github.com/belong2yourself/vulnerabilities/tree/master/ProVide/Web%20Admin%20Interface%20-%20Multiple%20Cross-Site-Scripting"}]}},"nvd":{"publishedDate":"2020-04-12 03:15:00","lastModifiedDate":"2020-04-13 17:16:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:provideserver:provide_ftp_server:*:*:*:*:*:windows:*:*","versionEndIncluding":"13.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"11704","Ordinal":"172398","Title":"CVE-2020-11704","CVE":"CVE-2020-11704","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"11704","Ordinal":"1","NoteData":"An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Web Interface has Multiple Stored and Reflected XSS. GetInheritedProperties is Reflected via the groups parameter. GetUserInfo is Reflected via POST data. SetUserInfo is Stored via the general parameter.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"11704","Ordinal":"2","NoteData":"2020-04-11","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"11704","Ordinal":"3","NoteData":"2020-04-11","Type":"Other","Title":"Modified"}]}}}