Property
Languagepython
Severitylow
CWECWE-319: Cleartext Transmission of Sensitive Information
OWASPA03:2017 - Sensitive Data Exposure
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

Using ftplib.FTP transmits all data, including login credentials, in plain text over the network. This exposes sensitive information to anyone who can intercept the traffic. To secure data in transit, use ftplib.FTP_TLS instead.

Impact#

If exploited, attackers could intercept and read usernames, passwords, and any files transferred between the client and server. This can lead to unauthorized access, data theft, or further compromise of user accounts and internal systems.