The product stores sensitive data under the FTP server root with insufficient access control, which might make it accessible to untrusted parties.
Avoid storing information under the FTP root directory.
Access control permissions should be set to prevent reading/writing of sensitive files inside/outside of the FTP directory.
Our security experts can help you identify and remediate CWE-220 vulnerabilities in your codebase.
Get Security Assessment