CVE-2019-13182
Description
A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A stored XSS vulnerability in SolarWinds Serv-U FTP Server 15.1.7 allows attackers to inject arbitrary JavaScript via the Full Name and HTTP Login Title Text fields.
Vulnerability
A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server version 15.1.7 [1]. The affected fields are Full Name and HTTP Login Title Text, which do not properly sanitize user-supplied input before storage, allowing arbitrary JavaScript to be injected [1].
Exploitation
An attacker can exploit this vulnerability by submitting malicious JavaScript code in the Full Name or HTTP Login Title Text fields through the web interface. No special network position is required beyond access to the affected web UI; both authenticated and unauthenticated users can trigger the stored XSS [1].
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser when the stored payload is rendered. This can lead to unauthorized actions performed in the user's security context, including session hijacking, credential theft, or other malicious actions [1].
Mitigation
SolarWinds released Serv-U 15.1.7 Hotfix 2 to address this vulnerability [1]. Users should upgrade to this fixed version. No workaround is disclosed in the available references.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- SolarWinds/Serv-U FTP Serverdescription
- Range: = 15.1.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- packetstormsecurity.com/files/155672/Serv-U-FTP-Server-15.1.7-Persistent-Cross-Site-Scripting.htmlmitrex_refsource_MISC
- seclists.org/fulldisclosure/2019/Dec/32mitremailing-listx_refsource_FULLDISC
- www.themissinglink.com.au/security-advisories-cve-2019-13182mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.