Home

Description

CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin sessions.

PUBLISHED Reserved 2025-10-27 | Published 2025-11-07 | Updated 2025-11-10 | Assigner mitre

References

gist.github.com/MMAKINGDOM/791d264c27656f0a4aa3c0ae35075e70

github.com/MMAKINGDOM/CVE-2025-63420/

cve.org (CVE-2025-63420)

nvd.nist.gov (CVE-2025-63420)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.