CVE-2023-42659: Progress WS_FTP Server

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

In WS_FTP Server versions prior to 8.7.6 and 8.8.4, an unrestricted file upload flaw has been identified. An authenticated Ad Hoc Transfer user has the ability to craft an API call which allows them to upload a file to a specified location on the underlying operating system hosting the WS_FTP Server application.

Affected products

  • Progress WS_FTP Server: before 8.7.6 (fixed in 8.7.6); from 8.8.0, before 8.8.4 (fixed in 8.8.4)

Published 2023-11-07. Last modified 2026-06-17.