PT-2024-17383 · Crushftp · Crushftp

Published

2024-12-13

·

Updated

2024-12-14

·

CVE-2024-11986

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue involves improper input handling in the 'Host Header', allowing an unauthenticated attacker to store a payload in web application logs. When an administrator views the logs, it enables the execution of the payload, resulting in Stored XSS or 'Cross-Site Scripting'.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-11986

Affected Products

Crushftp