CVE-2024-7744

MEDIUM

WS_FTP Server < 8.8.8 - Authenticated Path Traversal via Web Transfer Module

Title source: llm
STIX 2.1

Description

In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Web Transfer Module allows File Discovery, Probe System Files, User-Controlled Filename, Path Traversal.   An authenticated file download flaw has been identified where a user can craft an API call that allows them to download a file from an arbitrary folder on the drive where that user host's root folder is located (by default this is C:)

References (2)

Core 2

Scores

CVSS v3 6.5
EPSS 0.0031
EPSS Percentile 54.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22 CWE-73
Status published
Products (1)
progress/ws_ftp_server < 8.8.8
Published Aug 28, 2024
Tracked Since Feb 18, 2026