CyberSec.Space Logo
CVEブラウザに戻る

CVE-2025-63420

MEDIUM
4.1
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-11-07
Last Modified2026-06-17
Data SourcesNVD

Vulnerability Description

CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin sessions.

Affected Platforms (CPE)

📦
Crushftp

Crushftp

>= 11.0.1 and < 11.3.7_57

References & Advisories

関連する脆弱性情報