Cross-site scripting in Serv-U FTP Server - CVE-2026-28315
Published: July 27, 2026
Serv-U FTP Server
Detailed vulnerability description
The vulnerability allows a remote user to hijack an administrator session or disclose sensitive information.
The vulnerability exists due to cross-site scripting in Serv-U when processing stored content. A remote privileged user can inject a crafted script to hijack an administrator session or disclose sensitive information.
User interaction is required for an administrator to view the stored malicious content.