CVE-2023-40046: WS_FTP Server SQL Injection via Administrative Interface
In WSFTP Server versions prior to 8.7.4 and 8.8.2,
a SQL injection vulnerability exists in the WSFTP Server manager interface. An attacker may be able to infer information about the structure and contents of the database and execute SQL statements that alter or delete database elements.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-40046?
CVE-2023-40046 is a SQL injection vulnerability in WS_FTP Server versions prior to 8.7.4 and 8.8.2.
How does the SQL injection vulnerability in WS_FTP Server work?
The SQL injection vulnerability in WS_FTP Server allows an attacker to execute SQL statements that can alter or delete database elements.
What is the severity of CVE-2023-40046?
The severity of CVE-2023-40046 is high with a CVSS score of 7.2.
What software versions are affected by CVE-2023-40046?
WS_FTP Server versions prior to 8.7.4 and 8.8.2 are affected by CVE-2023-40046.
How can I fix CVE-2023-40046?
To fix CVE-2023-40046, update WS_FTP Server to version 8.7.4 or 8.8.2 depending on your current version.