Wing FTP Server before 7.4.4 does not properly validate...
Low severity
Unreviewed
Published
Jul 10, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Jul 10, 2025
Published to the GitHub Advisory Database
Jul 10, 2025
Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If a user clicks a crafted link, this discloses a cleartext password to the attacker.
References