CVE-2025-63420
07.11.2025, 22:15
A stored cross-site scripting (XSS) vulnerability in the CrushFTP 11.3.7_50 Admin Panel (Reports / 'Who Created Folder') allows authenticated attackers with permissions to create folders to inject malicious HTML/JavaScript.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.