Vulnerabilità · 196 giorni fa

CISA Adds Exploited Wing FTP Path Disclosure to KEV

CISA added CVE-2025-47813, a Wing FTP Server information-disclosure flaw, to its Known Exploited Vulnerabilities list after evidence of active exploitation. The medium-severity bug discloses the server's full local installation path via an overlong UID cookie; it was fixed in Wing FTP Server 7.4.4 but can aid attackers in chaining to other flaws.

CVE-2025-47813

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 4.3 MEDIUM: loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using… EPSS 63% (99º percentile).

Data di correzione federale CISA 30 mar

Cronologia

Fonti

3 fonti che coprono questa storia

Entità

Part of the PlainSec briefing for 2026-03-25

Editions

Storie correlate