CVE-2023-40048: Progress WS_FTP Server
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
In WS_FTP Server version prior to 8.8.2, the WS_FTP Server Manager interface was missing cross-site request forgery (CSRF) protection on a POST transaction corresponding to a WS_FTP Server administrative function.
Affected products
- Progress WS_FTP Server: before 8.8.2 (fixed in 8.8.2)
Published 2023-09-27. Last modified 2026-06-17.