CVE-2023-37878: Insecure Default Permissions in Wing FTP Server <= 7.2.0
Published Sep 12, 2023
·Updated
Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.
Affected Software
1 affected component
Wftpserver Wing Ftp Server<=7.2.0
Event History
Sep 12, 2023
CVE Published
via MITRE·08:16 AM
Data Sourced
via MITRE·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-37878.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation'.
3
What is the severity of CVE-2023-37878?
The severity of CVE-2023-37878 is high with a score of 8.8.
4
Which versions of Wing FTP Server are affected by CVE-2023-37878?
Wing FTP Server versions <= 7.2.0 are affected by CVE-2023-37878.
5
How can I fix the vulnerability CVE-2023-37878?
To fix the vulnerability CVE-2023-37878, update Wing FTP Server to a version higher than 7.2.0.