CVE-2023-40049: WS_FTP Server Information Disclosure via Directory Listing
Published Sep 27, 2023
·Updated
In WSFTP Server version prior to 8.8.2,
an unauthenticated user could enumerate files under the 'WebServiceHost' directory listing.
Affected Software
1 affected component
Progress Ws Ftp Server<8.8.2
Event History
Sep 27, 2023
CVE Published
via MITRE·02:52 PM
Data Sourced
via MITRE·02:52 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-40049.
2
What is the severity of CVE-2023-40049?
The severity of CVE-2023-40049 is medium with a severity value of 5.3.
3
What software is affected by CVE-2023-40049?
Progress WS FTP Server version prior to 8.8.2 is affected by CVE-2023-40049.
4
Is authentication required to exploit CVE-2023-40049?
No, CVE-2023-40049 can be exploited by an unauthenticated user.
5
What actions can an attacker do using CVE-2023-40049?
An attacker can enumerate files under the 'WebServiceHost' directory listing using CVE-2023-40049.