← Back to CVE List
Vulnerability Intelligence Report
Wing FTP Server Information Disclosure Vulnerability

CVE-2025-47813

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

CISA KEV Nuclei Template SSVC: Active Exploitation
CVSS Base Score
4.3
MEDIUM
Exploitability:2.9
Impact Score:1.5
EPSS Probability:56.37%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-209 ↗CWE-209 Generation of Error Message Containing Sensitive Information

Affected Products & Versions

Vendor Product Affected Versions
wftpserver Wing FTP Server 0 < 7.4.4 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
56.366%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2025-05-10T00:00:00
Published2025-07-10T00:00:00
Last Updated2026-03-17T12:41:40

LINK COPIED TO CLIPBOARD