Home

Description

A stored cross-site scripting (XSS) vulnerability in the CrushFTP 11.3.7_50 Admin Panel (Reports / 'Who Created Folder') allows authenticated attackers with permissions to create folders to inject malicious HTML/JavaScript.

PUBLISHED Reserved 2025-10-27 | Published 2025-11-07 | Updated 2025-11-07 | Assigner mitre

References

gist.github.com/MMAKINGDOM/791d264c27656f0a4aa3c0ae35075e70

github.com/MMAKINGDOM/CVE-2025-63420/

cve.org (CVE-2025-63420)

nvd.nist.gov (CVE-2025-63420)

Download JSON