CVE-2024-11986
EUVD-2024-3424113.12.2024, 14:15
Improper input handling in the 'Host Header' allows an unauthenticated attacker to store a payload in web application logs. When an Administrator views the logs using the application's standard functionality, it enables the execution of the payload, resulting in Stored XSS or 'Cross-Site Scripting'.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| crushftp | crushftp | 10.0.0 ≤ 𝑥 < 10.8.2 | CNA |
| crushftp | crushftp | 11.0.0 ≤ 𝑥 < 11.2.1 | CNA |