CVE-2025-63420

MEDIUM

CrushFTP 11.0.1-11.3.7_57 - Stored Cross-Site Scripting in Admin Panel Reports

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2025-63420. PoCs published by MMAKINGDOM, hossainshadat.

AI-analyzed exploit summary This repository contains a writeup for CVE-2025-63420, a stored HTML injection vulnerability in CrushFTP11 before 11.3.7_57. The vulnerability allows authenticated attackers to inject malicious HTML code in the Admin Panel's 'Who Created Folder' report.

Description

CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin sessions.

Exploits (2)

nomisec WRITEUP 2 stars
by MMAKINGDOM · poc
https://github.com/MMAKINGDOM/CVE-2025-63420

This repository contains a writeup for CVE-2025-63420, a stored HTML injection vulnerability in CrushFTP11 before 11.3.7_57. The vulnerability allows authenticated attackers to inject malicious HTML code in the Admin Panel's 'Who Created Folder' report.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: CrushFTP11 before 11.3.7_57
Auth required
Prerequisites: Authenticated access to CrushFTP Admin Panel · Permissions to create folders
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by hossainshadat · poc
https://github.com/hossainshadat/CVE-2025-63420

This repository documents a stored HTML injection (XSS) vulnerability in CrushFTP11 before 11.3.7_57, where authenticated attackers can inject malicious HTML via folder creation in the admin panel. The writeup includes steps to reproduce and references vendor patches.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: CrushFTP11 before 11.3.7_57
Auth required
Prerequisites: Authenticated access to CrushFTP Admin Panel · Permissions to create folders
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 4.1
EPSS 0.0023
EPSS Percentile 13.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
crushftp/crushftp 11.0.1 - 11.3.7_57
Published Nov 07, 2025
Tracked Since Feb 18, 2026