In WS_FTP Server versions prior to 8.7.6 and 8.8.4, an unrestricted file upload flaw has been identified. An authenticated Ad Hoc Transfer user has the ability to craft an API call which allows them to upload a file to a specified location on the underlying operating system hosting the WS_FTP Server application.
References
Link | Resource |
---|---|
https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-November-2023 | Vendor Advisory |
https://www.progress.com/ws_ftp | Product |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: ProgressSoftware
Published: 2023-11-07T15:13:40.001Z
Updated: 2023-11-07T15:13:40.001Z
Reserved: 2023-09-12T13:30:29.571Z
Link: CVE-2023-42659
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-11-07T16:15:28.923
Modified: 2023-11-14T20:21:09.777
Link: CVE-2023-42659
JSON object: View
Redhat Information
No data.
CWE