In WS_FTP Server versions before 8.8.8 (2022.0.8), a...
Moderate severity
Unreviewed
Published
Aug 28, 2024
to the GitHub Advisory Database
•
Updated Sep 4, 2024
Description
Published by the National Vulnerability Database
Aug 28, 2024
Published to the GitHub Advisory Database
Aug 28, 2024
Last updated
Sep 4, 2024
In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.
References