CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions.
Metrics
Affected Vendors & Products
References
History
Fri, 13 Jun 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Crushftp
Crushftp crushftp |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Crushftp
Crushftp crushftp |
Wed, 16 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Apr 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 15 Apr 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 15 Apr 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-40 | |
| Metrics |
cvssV3_1
|
Tue, 15 Apr 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-04-15T00:00:00.000Z
Updated: 2025-04-16T14:51:43.229Z
Reserved: 2025-04-04T00:00:00.000Z
Link: CVE-2025-32103
Updated: 2025-04-16T14:51:38.176Z
Status : Analyzed
Published: 2025-04-15T13:15:54.893
Modified: 2025-06-13T12:43:22.290
Link: CVE-2025-32103
No data.