CVE-2025-63420
MEDIUMCrushFTP 11.0.1-11.3.7_57 - Stored Cross-Site Scripting in Admin Panel Reports
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2025-63420. PoCs published by MMAKINGDOM, hossainshadat.
AI-analyzed exploit summary This repository contains a writeup for CVE-2025-63420, a stored HTML injection vulnerability in CrushFTP11 before 11.3.7_57. The vulnerability allows authenticated attackers to inject malicious HTML code in the Admin Panel's 'Who Created Folder' report.
Description
CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin sessions.
Exploits (2)
This repository contains a writeup for CVE-2025-63420, a stored HTML injection vulnerability in CrushFTP11 before 11.3.7_57. The vulnerability allows authenticated attackers to inject malicious HTML code in the Admin Panel's 'Who Created Folder' report.
This repository documents a stored HTML injection (XSS) vulnerability in CrushFTP11 before 11.3.7_57, where authenticated attackers can inject malicious HTML via folder creation in the admin panel. The writeup includes steps to reproduce and references vendor patches.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N