Vulnerabilities > Wftpserver > Wing FTP Server > 4.2.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-09-12 | CVE-2023-37875 | Improper Encoding or Escaping of Output vulnerability in Wftpserver Wing FTP Server Improper encoding or escaping of output in Wing FTP Server (User Web Client) allows Cross-Site Scripting (XSS).This issue affects Wing FTP Server: <= 7.2.0. | 5.4 |
2023-09-12 | CVE-2023-37878 | Incorrect Default Permissions vulnerability in Wftpserver Wing FTP Server Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0. | 8.8 |
2023-09-12 | CVE-2023-37879 | Insecure Storage of Sensitive Information vulnerability in Wftpserver Wing FTP Server Insecure storage of sensitive information in Wing FTP Server (User Web Client) allows information elicitation.This issue affects Wing FTP Server: <= 7.2.0. | 7.5 |
2023-09-12 | CVE-2023-37881 | Incorrect Authorization vulnerability in Wftpserver Wing FTP Server Weak access control in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0. | 8.8 |
2020-03-07 | CVE-2020-9470 | Incorrect Permission Assignment for Critical Resource vulnerability in Wftpserver Wing FTP Server An issue was discovered in Wing FTP Server 6.2.5 before February 2020. | 7.8 |