CVE-2018-20684
In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the s
In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the server, potentially overwriting unrelated files. This affects TSCPFileSystem::SCPSink in core/ScpFileSystem.cpp.
HIGH · CVSS 7.5
EPSS 0.0057
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0