Vulnerability Description
In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Web Transfer Module allows File Discovery, Probe System Files, User-Controlled Filename, Path Traversal. An authenticated file download flaw has been identified where a user can craft an API call that allows them to download a file from an arbitrary folder on the drive where that user host's root folder is located (by default this is C:)
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Progress | Ws Ftp Server | < 8.8.8 |
Related Weaknesses (CWE)
References
- https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-August-2024Vendor Advisory
- https://www.progress.com/ftp-serverProduct
FAQ
What is CVE-2024-7744?
CVE-2024-7744 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Web Transfer Module allows File Discovery, Pro...
How severe is CVE-2024-7744?
CVE-2024-7744 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-7744?
Check the references section above for vendor advisories and patch information. Affected products include: Progress Ws Ftp Server.