SolarWinds Serv-U FTP Server versions through 15.2.1 do not correctly sanitize and validate the user-supplied directory names, allowing malicious users to create directories that when clicked on (in the breadcrumb menu) will trigger cross site scripting payloads.
63b2c20217bc49cd26d5d1117a3e0ef300ddd3efe77e545937de5ae02474c7ac