Medium severity5.4NVD Advisory· Published Jul 18, 2017· Updated May 13, 2026
CVE-2017-5247
CVE-2017-5247
Description
Biscom Secure File Transfer is vulnerable to cross-site scripting in the File Name field. An authenticated user with permissions to upload or send files can populate this field with a filename that contains standard HTML scripting tags. The resulting script will evaluated by any other authenticated user who views the attacker-supplied file name. All versions of SFT prior to 5.1.1028 are affected. The fix version is 5.1.1028.
Affected products
2prior to 5.1.1028+ 1 more
- (no CPE)range: prior to 5.1.1028
- cpe:2.3:a:biscom:secure_file_transfer:-:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- twitter.com/i_bo0om/status/885050741567750145nvdThird Party Advisory
- cve.biscom.com/bis-sft-cv-0005/nvd
News mentions
0No linked articles in our index yet.