The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NCerberusftp Ftp Server
APPCerberusftp< 10.0.1911.0.0 – 11.0.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
Related vulnerabilities
CVE-2026-6265HIGH7.3same product
Insecure preserved inherited permissions vulnerability in Cerberus FTP Server on Windows allows Privilege Esca...
CVE-2020-5196HIGH8.1same product
Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 allows an authenticated attacker t...
CVE-2017-6367HIGH7.5same product
In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. The attack method...
CVE-2020-5194MEDIUM5.4same product
The zip API endpoint in Cerberus FTP Server 8 allows an authenticated attacker without zip permission to use t...
CVE-2020-5195MEDIUM6.1same product
Reflected XSS through an IMG element in Cerberus FTP Server prior to versions 11.0.1 and 10.0.17 allows a remo...