MEDIUM
Cross-site scripting (XSS) vulnerability in the file browser in Guacamole 0.9.8 and 0.9.9, when file transfer is enabled to a location shared by multiple users, allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename
Published Feb 2, 2017
5.4
MEDIUMCVSS 3.0
EPSS 2.22%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.