CVE-2025-27889: High severity Wing FTP Server vulnerability
Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If a user clicks a crafted link, this discloses a cleartext password to the attacker.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27889?
CVE-2025-27889 is considered a high severity vulnerability due to the potential for arbitrary link injection and disclosure of cleartext passwords.
How do I fix CVE-2025-27889?
To fix CVE-2025-27889, upgrade to Wing FTP Server version 7.4.4 or later, where the url parameter is properly validated and sanitized.
What kind of attack can result from CVE-2025-27889?
CVE-2025-27889 allows attackers to use crafted links to obtain sensitive cleartext passwords from vulnerable systems.
Is CVE-2025-27889 exploitable remotely?
Yes, CVE-2025-27889 is remotely exploitable as it involves user interaction with a malicious link.
What software versions are affected by CVE-2025-27889?
Wing FTP Server versions prior to 7.4.4 are affected by CVE-2025-27889.