QID 27395

Date Published: 2023-09-29

QID 27395: Progress WS_FTP Server Multiple Vulnerabilities

Progress had addressed multiple critical vulnerabilities in its WS-FTP Server, a popular FTP server for Microsoft Windows platforms.

Affected Versions:
WS_FTP Server versions prior to 8.7.4 and 8.8.2

QID Detection Logic
This QID checks for Vulnerable version of progress WS_FTP Server

Vulnerable versions of WS_FTP server are prone to the following vulnerabilities:
CVE-2023-40044 (CRITICAL) : A pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.
CVE-2023-42657 (CRITICAL) : A directory traversal vulnerability
CVE-2023-40045 (HIGH) : A reflected cross-site scripting (XSS) vulnerability
CVE-2023-40046 (HIGH) : A SQL injection vulnerability
CVE-2023-40047 (HIGH) : A stored cross-site scripting (XSS) vulnerability
CVE-2023-40048 (MEDIUM) : A cross-site request forgery (CSRF)
CVE-2022-27665 (MEDIUM) : Reflected cross-site scripting (XSS) (via AngularJS sandbox escape expressions)
CVE-2023-40049 (MEDIUM) : An unauthenticated user could enumerate files under the 'WebServiceHost' directory listing.

  • CVSS V3 rated as Critical - 9.6 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Upgrade to WS_FTP Server 8.7.4, 8.8.2 or later. Please refer to WS_FTP Server for more information.
    Software Advisories
    Advisory ID Software Component Link
    WS_FTP 000241298 URL Logo community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023