CVE-2025-63420
EUVD-2025-3832507.11.2025, 22:15
CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin sessions.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| crushftp | crushftp | 11.0.1 ≤ 𝑥 < 11.3.7_57 |
𝑥
= Vulnerable software versions