vendor:
FileZilla FTP client
by:
7.5
CVSS
HIGH
Password Disclosure
256
CWE
Product Name: FileZilla FTP client
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:filezilla_project:filezilla_ftp_client
Platforms Tested: Windows
FileZilla FTP client local password disclosure vulnerability
FileZilla FTP client may allow local attackers to obtain user passwords and access remote servers. The application uses a hard-coded cipher key to decrypt the password, which is stored in an XML file or the Windows Registry. This can allow the attacker to gain access to an FTP server with the privileges of the victim.
Mitigation:
The vendor should update the application to use a secure method for storing and decrypting passwords, such as using a strong encryption algorithm with a unique key for each user. Users should also ensure they are using the latest version of FileZilla FTP client and regularly update their software to receive security patches.