PT-2025-36965 · Unknown · Ftp-Flask-Python
Spendroslav
·
Published
2025-09-09
·
Updated
2025-09-10
·
CVE-2025-57633
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
FTP-Flask-python versions through 5173b68
Description:
A command injection issue exists in FTP-Flask-python. The
/ftp.html endpoint’s "Upload File" action constructs a shell command from the ftp file parameter and executes it using os.system() without sanitization or escaping, allowing unauthenticated remote attackers to execute arbitrary OS commands.Recommendations:
Versions prior to 5173b68 are affected.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ftp-Flask-Python