Sploitus

CVE-2025-27889

1 known exploit for CVE-2025-27889

Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If a user clicks a crafted link, this discloses a cleartext password to the attacker.

Affected products
Wing Ftp Server
Wftpserver Wing Ftp Server
< 7.4.4
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
0.4% (34th percentile)
Weakness
CWE-15
NVD status
Analyzed
Published
2025-07-10
CVE-2025-27889 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2025-27889

Proof-of-concept code and exploit modules indexed by Sploitus