Wing FTP Server
cpe:2.3:a:wftpserver:wing_ftp_server:*:*:*:*:*:*:*
- <= 8.1.2
A remote code execution vulnerability has been identified in Wing FTP Server version 8.1.2. This issue arises from the session serialization process, which allows authenticated administrators to inject arbitrary Lua code through the domain admin mydirectory field. The vulnerability exploits the unsafe serialization of session values into Lua source code, as closing delimiters are not properly escaped. Consequently, the injected code is executed when the compromised session is loaded using the loadfile() function.
Exploitation of this vulnerability allows for authenticated remote code execution on the server.
Users can upgrade to Wing FTP Server version 8.1.3 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.