loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.
2025-07-10T17:15:47.403
2025-07-17T13:17:06.690
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | wftpserver | wing_ftp_server | < 7.4.4 | Yes |