CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 15 Apr 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 15 Apr 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 15 Apr 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-40 | |
Metrics |
cvssV3_1
|
Tue, 15 Apr 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-04-15T00:00:00.000Z
Updated: 2025-04-16T14:51:43.229Z
Reserved: 2025-04-04T00:00:00.000Z
Link: CVE-2025-32103

Updated: 2025-04-16T14:51:38.176Z

Status : Awaiting Analysis
Published: 2025-04-15T13:15:54.893
Modified: 2025-04-16T15:16:12.310
Link: CVE-2025-32103

No data.