CVE-2019-9648: Coreftp Core FTP

Medium severity, CVSS 5.3. EPSS: 14.3% chance of exploitation in the next 30 days.

An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information.

Affected products

Published 2019-03-22. Last modified 2026-06-17.