Vulnerabilities (CVE)

Filtered by vendor Winscp Subscribe
Filtered by product Winscp
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-20684 1 Winscp 1 Winscp 2020-01-15 6.4 MEDIUM 7.5 HIGH
In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the server, potentially overwriting unrelated files. This affects TSCPFileSystem::SCPSink in core/ScpFileSystem.cpp.