Description
A stored cross-site scripting (XSS) vulnerability in the CrushFTP 11.3.7_50 Admin Panel (Reports / 'Who Created Folder') allows authenticated attackers with permissions to create folders to inject malicious HTML/JavaScript.
References
gist.github.com/MMAKINGDOM/791d264c27656f0a4aa3c0ae35075e70
github.com/MMAKINGDOM/CVE-2025-63420/