PT-2026-55447 · Sftpgo · Sftpgo
CVE-2026-49245
·
Published
2026-07-02
·
Updated
2026-08-21
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SFTPGo versions prior to 2.7.3
Description
A stored Cross-Site Scripting (XSS) issue exists where the
inline query parameter on the browsable-share file download and authenticated user file download endpoints suppresses the Content-Disposition: attachment header. This allows an HTML file stored in a share or home directory to be served as text/html and executed within the SFTPGo web origin. Exploitation requires an attacker to upload a crafted file and a victim to open the link via social engineering. Because session cookies are HttpOnly, they cannot be read by the injected script.Recommendations
Upgrade to version 2.7.3.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sftpgo