CVE-2023-37879: Exposed Session Variable in Wing FTP Server <= 7.2.0
Published Sep 12, 2023
·Updated
Insecure storage of sensitive information in Wing FTP Server (User Web Client) allows information elicitation.This issue affects Wing FTP Server: <= 7.2.0.
Affected Software
1 affected component
Wftpserver Wing Ftp Server<=7.2.0
Event History
Sep 12, 2023
CVE Published
via MITRE·08:15 AM
Data Sourced
via MITRE·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-37879?
CVE-2023-37879 is a vulnerability in Wing FTP Server (User Web Client) where sensitive information can be insecurely stored, allowing for information elicitation.
2
How does the vulnerability in Wing FTP Server (User Web Client) occur?
The vulnerability occurs due to insecure storage of sensitive information in Wing FTP Server (User Web Client).
3
Which version of Wing FTP Server is affected by CVE-2023-37879?
Wing FTP Server version 7.2.0 and earlier are affected by CVE-2023-37879.
4
What is the severity of CVE-2023-37879?
CVE-2023-37879 has a severity rating of 7.5 (High).
5
How can I fix the vulnerability in Wing FTP Server (User Web Client)?
To fix the vulnerability, it is recommended to update Wing FTP Server to a version higher than 7.2.0.