vendor:
CrushFTP
by:
N/A
5.5
CVSS
MEDIUM
CSRF & XSS
352, 79
CWE
Product Name: CrushFTP
Affected Version From: 7.2.2000
Affected Version To: 7.2.2000
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
N/A
Multiple CSRF & Cross-Site Scripting (XSS) vulnerabilities in Crushftp 7.2.0
Multiple CSRF & Cross-Site Scripting (XSS) vulnerabilities have been identified in Crushftp 7.2.0 (Web Interface) on default configuration. These vulnerabilities allows an attacker to gain control over valid user accounts, perform operations on their behalf, redirect them to malicious sites, steal their credentials, and more.
Mitigation:
User management includes inheritance, groups, and virtual file systems. CrushFTP is also watching out for common hack attempts and robots which scan for weak passwords and will automatically protect against DDoS attacks.