CVE-2024-1474
HIGHWS_FTP Server < 8.8.5 - Reflected Cross-Site Scripting in Administrative Interface
Title source: llmDescription
In WS_FTP Server versions before 8.8.5, reflected cross-site scripting issues have been identified on various user supplied inputs on the WS_FTP Server administrative interface.
References (2)
Core 2
Core References
Product product
https://www.progress.com/ws_ftp
Vendor Advisory vendor-advisory
https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-February-2024
Scores
CVSS v3
7.5
EPSS
0.0005
EPSS Percentile
16.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (1)
progress/ws_ftp_server
< 8.8.5
Published
Feb 21, 2024
Tracked Since
Feb 18, 2026