Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
738 articles · 106207 vulns · 36/50 feeds (7d)
← Back to list
4.3
CVE-2025-47813KEV

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

Description

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

Affected Products

VendorProductVersions
wftpserverwing_ftp_server< 7.4.4

References

  • https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2025-47813.txt(Exploit, Third Party Advisory)
  • https://www.rcesecurity.com/2025/06/what-the-null-wing-ftp-server-rce-cve-2025-47812/(Exploit, Third Party Advisory)
  • https://www.wftpserver.com(Product)
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-47813(US Government Resource)

Related News (1 articles)

Tier B
CERT-FR2d ago
Bulletin d'actualité CERTFR-2026-ACT-012 (23 mars 2026)
→ No new info (linked only)
CVSS 3.14.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA KEV✅ Yes
Actively exploited✅ Yes
CWECWE-209
Published7/10/2025
Last enriched4h ago
Trending Score67
Source articles1
Independent1
Info Completeness10/14
Missing: epss, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: verified
Confidence: 100%