vendor:
CrushFTP
by:
Abdualhadi khalifa
7.1
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: CrushFTP
Affected Version From: Below 10.7.1
Affected Version To: 36536
Patch Exists: YES
Related CWE:
CPE: a:crushftp:crushftp
Platforms Tested: Windows 10
2024
CrushFTP Directory Traversal
The CrushFTP server version below 10.7.1 and 11.1.0, including legacy 9.x, is vulnerable to directory traversal. An attacker can exploit this vulnerability to access sensitive files on the server by manipulating the file path in the URL.
Mitigation:
Update CrushFTP server to version 10.7.1 or higher to prevent directory traversal attacks.