Security Advisory

CVE-2025-27889

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-10 00:00:00
Last updated 2025-07-10 18:04:56
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If a user clicks a crafted link, this discloses a cleartext password to the attacker.