VYPR
Unrated severityNVD Advisory· Published Feb 6, 2026· Updated Mar 5, 2026

Wing FTP Server < 6.2.7 - Cross-site Request Forgery

CVE-2020-37079

Description

Wing FTP Server versions prior to 6.2.7 contain a cross-site request forgery (CSRF) vulnerability in the web administration interface that allows attackers to delete admin users. Attackers can craft a malicious HTML page with a hidden form to submit a request that deletes the administrative user account without proper authorization.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.