CVE-2024-7744: Progress WS_FTP Server

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Web Transfer Module allows File Discovery, Probe System Files, User-Controlled Filename, Path Traversal.   An authenticated file download flaw has been identified where a user can craft an API call that allows them to download a file from an arbitrary folder on the drive where that user host's root folder is located (by default this is C:)

Affected products

  • Progress WS_FTP Server: before 8.8.8 (fixed in 8.8.8)

Published 2024-08-28. Last modified 2026-06-17.