Patched - Globalscape Terms
A is a software or configuration update released by Globalscape or applied by an administrator to modify one or more of these terms, typically to fix a security flaw or to enforce a new regulatory requirement.
: A patch for a configuration-specific bug that caused the EFT service to crash when Azure cloud connection profiles failed. Security Best Practices and Configuration "Patches" globalscape terms patched
July 2024 Software Affected: Globalscape EFT (Enterprise File Transfer) Vulnerability Type: Stored Cross-Site Scripting (XSS) Severity: High (CVSS 8.0+ depending on configuration) A is a software or configuration update released
: Addressed in EFT v8.3.2 (released February 2026), this patch upgraded the OpenSSL library to v3.6.1 to mitigate security risks associated with the underlying encryption toolkit. – An authenticated administrator (or an attacker who
– An authenticated administrator (or an attacker who compromised admin credentials) could inject malformed XML into custom “term sets” (e.g., a condition like IF user IP = 192.168.1.* THEN allow SFTP ). The injection could escape its logical container and overwrite global authentication policies.
