Critical severity9.1NVD Advisory· Published Nov 7, 2023· Updated Jun 17, 2026
CVE-2023-42659
CVE-2023-42659
Description
In WS_FTP Server versions prior to 8.7.6 and 8.8.4, an unrestricted file upload flaw has been identified. An authenticated Ad Hoc Transfer user has the ability to craft an API call which allows them to upload a file to a specified location on the underlying operating system hosting the WS_FTP Server application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <8.7.6, <8.8.4
- Progress Software Corporation/WS_FTP Serverv5Range: 8.8.0
Patches
Vulnerability mechanics
References
2- community.progress.com/s/article/WS-FTP-Server-Service-Pack-November-2023nvdVendor Advisory
- www.progress.com/ws_ftpnvdProduct
News mentions
0No linked articles in our index yet.