CVE-2023-40048

MEDIUM

WS_FTP Server < 8.8.2 - Cross-Site Request Forgery in Server Manager Interface

Title source: llm
STIX 2.1

Description

In WS_FTP Server version prior to 8.8.2, the WS_FTP Server Manager interface was missing cross-site request forgery (CSRF) protection on a POST transaction corresponding to a WS_FTP Server administrative function.

References (2)

Core 2

Scores

CVSS v3 6.8
EPSS 0.0055
EPSS Percentile 68.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
progress/ws_ftp_server < 8.8.2
Published Sep 27, 2023
Tracked Since Feb 18, 2026