First published: Wed Sep 27 2023(Updated: )
In WS_FTP Server version prior to 8.8.2, the WS_FTP Server Manager interface was missing cross-site request forgery (CSRF) protection on a POST transaction corresponding to a WS_FTP Server administrative function.
Credit: security@progress.com security@progress.com
Affected Software | Affected Version | How to fix |
---|---|---|
Progress Ws Ftp Server | <8.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-40048 is medium with a severity value of 6.8.
CVE-2023-40048 refers to a vulnerability in WS_FTP Server version prior to 8.8.2 where the WS_FTP Server Manager interface lacks cross-site request forgery (CSRF) protection.
CVE-2023-40048 affects WS_FTP Server versions prior to 8.8.2 by exposing the WS_FTP Server Manager interface to cross-site request forgery (CSRF) attacks on certain administrative functions.
To fix CVE-2023-40048, it is recommended to update WS_FTP Server to version 8.8.2 or later, which includes the necessary cross-site request forgery (CSRF) protection on the WS_FTP Server Manager interface.