QID 27396
QID 27396: Progress WS_FTP Server Reflected Cross-Site Scripting (XSS) Vulnerability
CVE-2024-1474: In WS_FTP Server versions before 8.8.5, reflected cross-site scripting issues have been identified on various user supplied inputs on the WS_FTP Server administrative interface.
Affected Versions:
WS_FTP Server versions before 8.8.5
QID Detection Logic
This QID checks for Vulnerable version of progress WS_FTP Server
Successful exploitation of this vulnerability may allow attacker to execute malicious JavaScript on the target system.
Solution
Upgrade to WS_FTP Server 8.8.5 or later. Please refer to WS_FTP Server Security Advisory for further information.
Vendor References
- WS_FTP Server Security Advisory -
community.progress.com/s/article/WS-FTP-Server-Service-Pack-February-2024
CVEs related to QID 27396
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WS_FTP Server Security Advisory |
|