CVE-2023-42659 CRITICAL

CVE-2023-42659: WS_FTP Server Arbitrary File Upload

Vendor Progress Software Corporation
Product WS_FTP Server
Weakness CWE-434 · Unrestricted file upload
Published November 7, 2023
Last update September 4, 2024

CVSS base score

9.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L

What the vulnerability does

01Description

In WS_FTP Server versions prior to 8.7.6 and 8.8.4, an unrestricted file upload flaw has been identified. An authenticated Ad Hoc Transfer user has the ability to craft an API call which allows them to upload a file to a specified location on the underlying operating system hosting the WS_FTP Server application.

Key dates

02Disclosure timeline

November 7, 2023 CVE published
September 4, 2024 Record updated