Логотип exploitDog
bind:CVE-2025-63420
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-63420

Количество 2

Количество 2

nvd логотип

CVE-2025-63420

3 месяца назад

CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin sessions.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-4pqv-hw6c-g45v

3 месяца назад

A stored cross-site scripting (XSS) vulnerability in the CrushFTP 11.3.7_50 Admin Panel (Reports / 'Who Created Folder') allows authenticated attackers with permissions to create folders to inject malicious HTML/JavaScript.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-63420

CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin sessions.

CVSS3: 4.1
0%
Низкий
3 месяца назад
github логотип
GHSA-4pqv-hw6c-g45v

A stored cross-site scripting (XSS) vulnerability in the CrushFTP 11.3.7_50 Admin Panel (Reports / 'Who Created Folder') allows authenticated attackers with permissions to create folders to inject malicious HTML/JavaScript.

0%
Низкий
3 месяца назад

Уязвимостей на страницу