cve/2018/CVE-2018-20684.md
2024-06-18 02:51:15 +02:00

781 B

CVE-2018-20684

Description

In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the server, potentially overwriting unrelated files. This affects TSCPFileSystem::SCPSink in core/ScpFileSystem.cpp.

POC

Reference

Github

No PoCs found on GitHub currently.