PT-2025-45509 · Crushftp · Crushftp

Published

2025-11-07

·

Updated

2026-02-05

·

CVE-2025-63420

CVSS v3.1

4.1

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions CrushFTP version 11.3.7 50
Description A stored cross-site scripting (XSS) issue exists in the CrushFTP Admin Panel, specifically within the Reports / 'Who Created Folder' section. Authenticated attackers who have folder creation permissions can inject malicious HTML or JavaScript code. The vulnerability allows for the execution of arbitrary code within the context of other users' browsers.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict folder creation permissions to trusted users only.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-63420

Affected Products

Crushftp