VYPR
Unrated severityNVD Advisory· Published Dec 16, 2019· Updated Aug 4, 2024

CVE-2019-13182

CVE-2019-13182

Description

A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A stored XSS vulnerability in SolarWinds Serv-U FTP Server 15.1.7 allows attackers to inject arbitrary JavaScript via the Full Name and HTTP Login Title Text fields.

Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server version 15.1.7 [1]. The affected fields are Full Name and HTTP Login Title Text, which do not properly sanitize user-supplied input before storage, allowing arbitrary JavaScript to be injected [1].

Exploitation

An attacker can exploit this vulnerability by submitting malicious JavaScript code in the Full Name or HTTP Login Title Text fields through the web interface. No special network position is required beyond access to the affected web UI; both authenticated and unauthenticated users can trigger the stored XSS [1].

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser when the stored payload is rendered. This can lead to unauthorized actions performed in the user's security context, including session hijacking, credential theft, or other malicious actions [1].

Mitigation

SolarWinds released Serv-U 15.1.7 Hotfix 2 to address this vulnerability [1]. Users should upgrade to this fixed version. No workaround is disclosed in the available references.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.