VYPR
High severity8.3NVD Advisory· Published Sep 27, 2023· Updated Jun 17, 2026

CVE-2023-40047

CVE-2023-40047

Description

In WS_FTP Server version prior to 8.8.2, a stored cross-site scripting (XSS) vulnerability exists in WS_FTP Server's Management module. An attacker with administrative privileges could import a SSL certificate with malicious attributes containing cross-site scripting payloads.  Once the cross-site scripting payload is successfully stored,  an attacker could leverage this vulnerability to target WS_FTP Server admins with a specialized payload which results in the execution of malicious JavaScript within the context of the victims browser.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:progress:ws_ftp_server:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:progress:ws_ftp_server:*:*:*:*:*:*:*:*range: <8.8.2
    • (no CPE)range: <8.8.2
    • (no CPE)range: 8.8.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.