Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If a user clicks a crafted link, this discloses a cleartext password to the attacker.
2025-07-10T17:15:46.683
2025-07-17T13:31:12.423
Analyzed
CVSSv3.1: 3.4 (LOW)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | wftpserver | wing_ftp_server | < 7.4.4 | Yes |