CVE-2025-47813
BaseFortify
Publication date: 2025-07-10
Last updated on: 2026-03-16
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wftpserver | wing_ftp_server | to 7.4.4 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-209 | The product generates an error message that includes sensitive information about its environment, users, or associated data. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability occurs in Wing FTP Server versions before 7.4.4, where the loginok.html page discloses the full local installation path of the application if a long value is used in the UID cookie. This means that an attacker can obtain information about the server's directory structure by manipulating the UID cookie.
How can this vulnerability impact me? :
The impact of this vulnerability is information disclosure. By revealing the full local installation path, it may aid an attacker in further attacks by providing insights into the server's file system layout. However, the vulnerability has a low severity score (CVSS 4.3) and does not directly affect integrity or availability.