Medium severity4.3CISA KEVNVD Advisory· Published Jul 10, 2025· Updated Jun 17, 2026
CVE-2025-47813
CVE-2025-47813
Description
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:wftpserver:wing_ftp_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:wftpserver:wing_ftp_server:*:*:*:*:*:*:*:*range: <7.4.4
- (no CPE)range: 0
- Range: <7.4.4
Patches
Vulnerability mechanics
References
4- github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2025-47813.txtnvdExploitThird Party Advisory
- www.rcesecurity.com/2025/06/what-the-null-wing-ftp-server-rce-cve-2025-47812/nvdExploitThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
- www.wftpserver.comnvdProduct
News mentions
0No linked articles in our index yet.