Medium severity4.3NVD Advisory· Published Feb 7, 2026· Updated Jun 17, 2026
CVE-2020-37079
CVE-2020-37079
Description
Wing FTP Server versions prior to 6.2.7 contain a cross-site request forgery (CSRF) vulnerability in the web administration interface that allows attackers to delete admin users. Attackers can craft a malicious HTML page with a hidden form to submit a request that deletes the administrative user account without proper authorization.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<6.2.7+ 1 more
- (no CPE)range: <6.2.7
- (no CPE)range: 6.2.6
Patches
Vulnerability mechanics
References
4- www.exploit-db.com/exploits/48200nvdExploitThird Party AdvisoryVDB Entry
- www.vulncheck.com/advisories/wing-ftp-server-cross-site-request-forgerynvdThird Party Advisory
- www.wftpserver.comnvdProduct
- www.wftpserver.com/serverhistory.htmnvdRelease Notes
News mentions
0No linked articles in our index yet.