CVE-2025-47813
Sfruttamento noto · CISA KEV
CVSS 4.3 MEDIUM: loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using… EPSS 63% (99º percentile).
Data di correzione federale CISA 30 mar
Vulnerabilità · 196 giorni fa
CISA added CVE-2025-47813, a Wing FTP Server information-disclosure flaw, to its Known Exploited Vulnerabilities list after evidence of active exploitation. The medium-severity bug discloses the server's full local installation path via an overlong UID cookie; it was fixed in Wing FTP Server 7.4.4 but can aid attackers in chaining to other flaws.
Sfruttamento noto · CISA KEV
CVSS 4.3 MEDIUM: loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using… EPSS 63% (99º percentile).
Data di correzione federale CISA 30 mar
3 fonti che coprono questa storia
CISA Flags Year-Old Wing FTP Vulnerability as Exploited
Tracked as CVE-2025-47813, the flaw leads to the disclosure of the full local installation path of the application.
CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths
CISA adds Wing FTP CVE-2025-47813 to KEV after active exploitation, exposing server paths and aiding attacks; patch by March 30, 2026.
CISA flags Wing FTP Server flaw as actively exploited in attacks
government agencies to secure their Wing FTP Server instances against an actively exploited vulnerability that may be chained in remote code execution attacks.
Part of the PlainSec briefing for 2026-03-25