Unrated severityNVD Advisory· Published Feb 6, 2026· Updated Mar 5, 2026
Wing FTP Server < 6.2.7 - Cross-site Request Forgery
CVE-2020-37079
Description
Wing FTP Server versions prior to 6.2.7 contain a cross-site request forgery (CSRF) vulnerability in the web administration interface that allows attackers to delete admin users. Attackers can craft a malicious HTML page with a hidden form to submit a request that deletes the administrative user account without proper authorization.
Affected products
2- Range: <6.2.7
- Wing FTP Server/Wing FTP Serverv5Range: 6.2.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.wftpserver.com/serverhistory.htmmitrepatch
- www.exploit-db.com/exploits/48200mitreexploit
- www.vulncheck.com/advisories/wing-ftp-server-cross-site-request-forgerymitrethird-party-advisory
- www.wftpserver.commitreproduct
News mentions
0No linked articles in our index yet.