CVE-2025-47813

MEDIUM CVSS 3.1: 4.3 EPSS 63.0% ACTIVE EXPLOIT
Updated Mar 16, 2026
Wftpserver

CISA Known Exploited Vulnerability (KEV)

This vulnerability is actively exploited in the wild. Immediate patching is strongly recommended.

Due Date: Mar 30, 2026

Parameter Value
CVSS 4.3 (MEDIUM)
Affected Versions before 7.4.4
Fixed In 7.4.4
Type CWE-209 (Information Exposure Through Error Message)
Vendor Wftpserver
Public PoC Yes

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Wftpserver Wing_Ftp_Server
cpe:2.3:a:wftpserver:wing_ftp_server:*:*:*:*:*:*:*:*
7.4.4