CVE-2023-37875: Cross-Site Scripting Vulnerability in Wing FTP Server <= 7.2.0
Published Sep 12, 2023
·Updated
Improper encoding or escaping of output in Wing FTP Server (User Web Client) allows Cross-Site Scripting (XSS).This issue affects Wing FTP Server: <= 7.2.0.
Affected Software
1 affected component
Wftpserver Wing Ftp Server<=7.2.0
Event History
Sep 12, 2023
CVE Published
via MITRE·08:17 AM
Data Sourced
via MITRE·08:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-37875.
2
What is the severity of CVE-2023-37875?
The severity of CVE-2023-37875 is medium with a CVSS score of 5.4.
3
Which software is affected by CVE-2023-37875?
Wing FTP Server versions up to and including 7.2.0 are affected by CVE-2023-37875.
4
What is the CWE ID of CVE-2023-37875?
The CWE ID of CVE-2023-37875 is CWE-79 and CWE-116.
5
How can I fix the CVE-2023-37875 vulnerability?
To fix the CVE-2023-37875 vulnerability, update Wing FTP Server to a version higher than 7.2.0.