Tools

Broken welcome message in Serv-U Web Client after upgrading to version 15.2.2

This article describes the behavior where the welcome message in Serv-U Web Client is broken after upgrading to version 15.2.2

First published date

2/9/2021 8:01 PM

Last published date

2/23/2021 8:48 PM

Overview

Serv-U allows using welcome messages in the Web Client feature for customers to provide more information such as how to use the Web Client, who to contact for support and such.
This is configured in Global / Domains > Limits & Settings > Settings tab > Custom HTTP Logo, Login Page Text & Title.



On previous versions, HTML codes and tags are allowed but it was removed on version 15.2.2.

Here is a sample of a broken welcome message.


 

Product section

Serv-U Managed File Transfer & Serv-U FTP Server

Resolution


We fixed some  XSS vulnerabilities present on previous versions, and as a result, HTML/javascript code will not work anymore as anything "HTML-encoded" will be rendered "as is". We recommend that you consider using the Custom HTML feature or not using HTML codes in the login message.

Below are our guides for using Custom HTML in Serv-U.
https://documentation.solarwinds.com/en/success_center/servu/Content/Help-Custom-HTML.htm
https://support.solarwinds.com/SuccessCenter/s/article/Serv-U-Custom-HTML-and-CSS-Advanced-Branding?language=en_US