4.1
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
Description
CVE-2025-63420 CrushFTP11 before 11.3.757 is vulnerable to stored HTML injection in the CrushFTP Admin Panel Reports / "Who Created Folder", enabling persistent HTML execution in admin sessions. CWE CWE-79 — Improper Neutralization of Input During Web...
Basic Information
ID
57EE0E7E-4A8C-58DD-88EE-8DD957B5137E
Published
Nov 27, 2025 at 07:10
Modified
Nov 27, 2025 at 07:13