Insecure File Permissions in Wing FTP Server v6.2.3 for Linux, macOS, and Solaris

Insecure File Permissions in Wing FTP Server v6.2.3 for Linux, macOS, and Solaris

CVE-2020-8634 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, resulting in files being saved with world-readable and world-writable permissions. If a sensitive system file were edited this way, a low-privilege user may escalate privileges to root.

Learn more about our Cis Benchmark Audit For Apple Macos.