TROYANOSYVIRUS
Back to CVEs

CVE-2020-37079

MEDIUM
4.3

Description

Wing FTP Server versions prior to 6.2.7 contain a cross-site request forgery (CSRF) vulnerability in the web administration interface that allows attackers to delete admin users. Attackers can craft a malicious HTML page with a hidden form to submit a request that deletes the administrative user account without proper authorization.

CVE Details

CVSS v3.1 Score4.3
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published2/7/2026
Last Modified2/18/2026
Sourcenvd
Honeypot Sightings0

Affected Products

wftpserver:wing_ftp_server

Weaknesses (CWE)

CWE-352

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.