Description
Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
Any version
Credits
Sonny of watchTowr
References
www.monstaftp.com/notes/
labs.watchtowr.com/...-remote-code-execution-cve-2025-34299/
www.vulncheck.com/...p-unauthenticated-arbitrary-file-upload