8.6
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N
Description
Wing FTP Server v8.1.2 contains a Remote Code Execution RCE vulnerability in the session serialization mechanism. An authenticated administrator can inject arbitrary Lua code through the domain admin mydirectory basefolder field, which gets executed...
Basic Information
ID
010D36EA-64D2-58CB-BBA2-67A76125216C
Published
May 14, 2026 at 06:58
Modified
May 14, 2026 at 07:02