CVE-2025-47813: Wing FTP Server Information Disclosure Vulnerability
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.
Other sources
Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wing FTP Serverto a version that resolves this vulnerability.Fixed in 7.4.4 - Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
Discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47813?
CVE-2025-47813 is classified as a medium severity vulnerability due to the potential risk of exposing sensitive file paths.
How can I fix CVE-2025-47813?
To mitigate CVE-2025-47813, update Wing FTP Server to version 7.4.4 or later, which addresses this issue.
What type of information does CVE-2025-47813 expose?
CVE-2025-47813 discloses the full local installation path of the Wing FTP Server application.
Which versions of Wing FTP Server are affected by CVE-2025-47813?
CVE-2025-47813 affects all versions of Wing FTP Server prior to 7.4.4.
Can CVE-2025-47813 be exploited remotely?
CVE-2025-47813 can potentially be exploited if an attacker crafts a long UID cookie, leading to information disclosure.