PT-2025-46678 · Crushftp · Crushftp

Almuntadhar0X01

+1

·

Published

2025-11-12

·

Updated

2025-12-31

·

CVE-2025-63419

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CrushFTP version 11.3.6 48
Description A Cross Site Scripting (XSS) issue exists in CrushFTP. The web-based server’s file sharing feature reflects the filename to an email body field without proper sanitization, leading to potential HTML injection. The vulnerability occurs when users share files.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-63419

Affected Products

Crushftp