CVE-2023-40045: WS_FTP Server Ad Hoc Transfer Module Reflected Cross-Site Scripting Vulnerability
In WSFTP Server versions prior to 8.7.4 and 8.8.2,
a reflected cross-site scripting (XSS) vulnerability exists in WSFTP Server's Ad Hoc Transfer module. An attacker could leverage this vulnerability to target WSFTP Server users with a specialized payload which results in the execution of malicious JavaScript within the context of the victims browser.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this WS_FTP Server vulnerability?
The vulnerability ID for this WS_FTP Server vulnerability is CVE-2023-40045.
What is the severity level of CVE-2023-40045?
The severity level of CVE-2023-40045 is high (6.1).
What is the affected software version range for CVE-2023-40045?
The affected software versions for CVE-2023-40045 are prior to 8.7.4 and 8.8.2.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-40045?
The Common Weakness Enumeration (CWE) ID for CVE-2023-40045 is CWE-79.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by leveraging a reflected cross-site scripting (XSS) vulnerability in WS_FTP Server's Ad Hoc Transfer module.