CVE-2014-9580
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) r561 allows remote attackers to inject arbitrary
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) r561 allows remote attackers to inject arbitrary web script or HTML via the Description field in a file upload. NOTE: this issue was originally incorrectly mapped to CVE-2014-1155.
see CVE-2014-1155 for more information.
MEDIUM · CVSS 4.3
EPSS 0.038
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0