CVE-2025-47813
Sfruttamento noto · CISA KEV
CVSS 4.3 MEDIUM: loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using… EPSS 63% (99º percentile).
Data di correzione federale CISA 30 mar
Vulnerabilità ed exploit · Attacco ad app web
CISA ha aggiunto CVE-2025-47813 al catalogo Known Exploited Vulnerabilities dopo evidenze di sfruttamento attivo. La falla espone il percorso di installazione locale tramite un UID cookie e può essere sfruttata in catene con altri bug di Wing FTP. La correzione è disponibile in Wing FTP Server 7.4.4.
3 fonti · 17 mar
Sfruttamento noto · CISA KEV
CVSS 4.3 MEDIUM: loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using… EPSS 63% (99º percentile).
Data di correzione federale CISA 30 mar
SecurityWeek
CISA Flags Year-Old Wing FTP Vulnerability as Exploited
Tracked as CVE-2025-47813, the flaw leads to the disclosure of the full local installation path of the application.
originaleThe Hacker News
CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths
CISA adds Wing FTP CVE-2025-47813 to KEV after active exploitation, exposing server paths and aiding attacks; patch by March 30, 2026.
originaleBleepingComputer
CISA flags Wing FTP Server flaw as actively exploited in attacks
government agencies to secure their Wing FTP Server instances against an actively exploited vulnerability that may be chained in remote code execution attacks.
originalePart of the PlainSec briefing for 2026-03-18
Every edition of this story: Vulnerabilità Wing FTP Server Aggiunta al KEV di CISA