In WS_FTP Server versions prior to 8.7.6 and 8.8.4, an...
High severity
Unreviewed
Published
Nov 14, 2023
to the GitHub Advisory Database
•
Updated Apr 10, 2024
Description
Published by the National Vulnerability Database
Nov 7, 2023
Published to the GitHub Advisory Database
Nov 14, 2023
Last updated
Apr 10, 2024
In WS_FTP Server versions prior to 8.7.6 and 8.8.4, an unrestricted file upload flaw has been identified. An authenticated Ad Hoc Transfer user has the ability to craft an API call which allows them to upload a file to a specified location on the underlying operating system hosting the WS_FTP Server application.