Description
SFTPGo is an SFTP server written in Go. Versions prior to 2.3.5 are subject to Cross-site scripting (XSS) vulnerabilities in the SFTPGo WebClient, allowing remote attackers to inject malicious code. This issue is patched in version 2.3.5. No known workarounds exist.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6779 | SFTPGo is an SFTP server written in Go. Versions prior to 2.3.5 are subject to Cross-site scripting (XSS) vulnerabilities in the SFTPGo WebClient, allowing remote attackers to inject malicious code. This issue is patched in version 2.3.5. No known workarounds exist. |
Github GHSA |
GHSA-cf7g-cm7q-rq7f | SFTPGo WebClient vulnerable to Cross-site Scripting |
References
History
Wed, 23 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T16:56:53.287Z
Reserved: 2022-09-02T00:00:00.000Z
Link: CVE-2022-39220
Updated: 2024-08-03T12:00:43.545Z
Status : Modified
Published: 2022-09-20T22:15:10.177
Modified: 2024-11-21T07:17:48.953
Link: CVE-2022-39220
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA