Kiteworks MFT
cpe:2.3:a:accellion:kiteworks_managed_file_transfer:*:*:*:*:*:*:*
- < 9.1.0
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Kiteworks MFT versions prior to 9.1.0. This vulnerability could enable an external attacker to access log information by deceiving an administrator into visiting a specially crafted fake page within Kiteworks MFT.
Exploitation of this vulnerability could lead to unauthorized access to log information from the affected system.
Users are advised to upgrade Kiteworks MFT to version 9.1.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.