Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2020-36502

Disclosure Date: October 22, 2021 (last updated February 23, 2025)
Swift File Transfer Mobile v1.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the devicename parameter which allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered as the device name itself.
Attacker Value
Unknown

CVE-2020-36486

Disclosure Date: October 22, 2021 (last updated February 23, 2025)
Swift File Transfer Mobile v1.1.2 and below was discovered to contain a cross-site scripting (XSS) vulnerability via the 'path' parameter of the 'list' and 'download' exception-handling.
Attacker Value
Unknown

CVE-2020-23038

Disclosure Date: October 22, 2021 (last updated February 23, 2025)
Swift File Transfer Mobile v1.1.2 and below was discovered to contain an information disclosure vulnerability in the path parameter. This vulnerability is exploited via an error caused by including non-existent path environment variables.