In WS_FTP Server versions prior to 8.7.4 and 8.8.2,
a SQL injection vulnerability exists in the WS_FTP Server manager interface. An attacker may be able to infer information about the structure and contents of the database and execute SQL statements that alter or delete database elements.
References
Link | Resource |
---|---|
https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023 | Vendor Advisory |
https://www.progress.com/ws_ftp | Product |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: ProgressSoftware
Published: 2023-09-27T14:50:18.549Z
Updated: 2023-09-27T15:23:03.495Z
Reserved: 2023-08-08T19:44:41.112Z
Link: CVE-2023-40046
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-09-27T15:18:58.103
Modified: 2023-09-27T19:33:00.803
Link: CVE-2023-40046
JSON object: View
Redhat Information
No data.
CWE