CVE-2025-47813
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.
- Affected products
- Wing Ftp Server
- Wftpserver Wing Ftp Server
- < 7.4.4
- Fix
- Available
- CVSS 3.1
- 4.3 MEDIUM
- EPSS
- 95.3% (100th percentile)
- Weakness
- CWE-209
- NVD status
- Analyzed
- Published
- 2025-07-10
CVE-2025-47813 at NVD
2 known exploits for CVE-2025-47813
Proof-of-concept code and exploit modules indexed by Sploitus