← Back

CVE-2025-27889

nvd nist
Published: Jul 10, 2025Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If a user clicks a crafted link, this discloses a cleartext password to the attacker.

Affected (1)

1 product
Wing Ftp Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 7.4.4

References (4)

Source: cve@mitre.org
Broken Link
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitThird Party Advisory

Timeline

No history available yet.