CVE-2023-40048: WS_FTP Server Cross-Site Request Forgery (CSRF) Vulnerability
In WSFTP Server version prior to 8.8.2,
the WSFTP Server Manager interface was missing cross-site request forgery (CSRF) protection on a POST transaction corresponding to a WSFTP Server administrative function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-40048?
The severity of CVE-2023-40048 is medium with a severity value of 6.8.
What is CVE-2023-40048?
CVE-2023-40048 refers to a vulnerability in WS_FTP Server version prior to 8.8.2 where the WS_FTP Server Manager interface lacks cross-site request forgery (CSRF) protection.
How does CVE-2023-40048 affect WS_FTP Server?
CVE-2023-40048 affects WS_FTP Server versions prior to 8.8.2 by exposing the WS_FTP Server Manager interface to cross-site request forgery (CSRF) attacks on certain administrative functions.
What is the fix for CVE-2023-40048?
To fix CVE-2023-40048, it is recommended to update WS_FTP Server to version 8.8.2 or later, which includes the necessary cross-site request forgery (CSRF) protection on the WS_FTP Server Manager interface.