Description
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote attackers to inject arbitrary web script or HTML via the Description field in a Site name updated.
Remediation
References
Related Vulnerabilities
PostgreSQL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2020-25694)
datatables Cross-site Scripting (XSS) Vulnerability (CVE-2015-6584)
IBM WebSEAL Insufficiently Protected Credentials Vulnerability (CVE-2021-20439)
MODX CVE-2017-7323 Vulnerability (CVE-2017-7323)
Apache HTTP Server Improper Input Validation Vulnerability (CVE-2011-3639)