SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functionality via ?Command=Upload with the Dir and File parameters.
References
Link | Resource |
---|---|
https://support.solarwinds.com/SuccessCenter/s/article/Serv-U-15-1-6-HotFix-2 | Release Notes Vendor Advisory |
https://medium.com/@clod81/cve-2019-12769-solarwinds-serv-u-managed-file-transfer-mft-web-client-15-1-6-a2dab98d668d | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-03-18 12:15
Updated : 2020-03-20 12:10
NVD link : CVE-2019-12769
Mitre link : CVE-2019-12769
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
solarwinds
- serv-u_managed_file_transfer