vendor:
CoreFTP Server
by:
LiamInfosec
6.5
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: CoreFTP Server
Affected Version From: build 725
Affected Version To: build 726
Patch Exists: YES
Related CWE: CVE-2022-22836
CPE: a:coreftp:coreftp_server
Platforms Tested: Windows 10
2022
CoreFTP Server build 725 – Directory Traversal (Authenticated)
CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.
Mitigation:
Upgrade to CoreFTP Server build 727 or later