Medium severity4.8NVD Advisory· Published Mar 21, 2019· Updated Jun 17, 2026
CVE-2018-19934
CVE-2018-19934
Description
SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3= 15.1.6.25+ 1 more
- (no CPE)range: = 15.1.6.25
- (no CPE)range: 15.1.6.25
- cpe:2.3:a:solarwinds:serv-u_ftp_server:15.1.6.25:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/151474/SolarWinds-Serv-U-FTP-15.1.6.25-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2019/Feb/5nvdMailing ListThird Party Advisory
- www.themissinglink.com.au/security-advisories-cve-2018-19934nvdThird Party Advisory
News mentions
0No linked articles in our index yet.