Description
Cross-site scripting (XSS) vulnerability in Accellion Secure File Transfer Appliance before 7_0_296 allows remote attackers to inject arbitrary web script or HTML via the username parameter, which is not properly handled when the administrator views audit logs.
Affected products
- Accellion / secure_file_transfer_appliance7_0_135 – 7_0_135
- Accellion / secure_file_transfer_appliance7_0_178 – 7_0_178
- Accellion / secure_file_transfer_appliance7_0_189 – 7_0_189
- Accellion / secure_file_transfer_appliance7_0_259 – 7_0_259