CrushFTP 10.8.4

CPE Details

CrushFTP 10.8.4
10.8.4
2025-04-08
17h17 +00:00
2025-04-08
17h17 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:crushftp:crushftp:10.8.4:*:*:*:*:*:*:*

Informations

Vendor

crushftp

Product

crushftp

Version

10.8.4

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2025-32102 2025-04-15 00h00 +00:00 CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request to the /WebInterface/function/ URI.
5
Moyen
CVE-2025-32103 2025-04-15 00h00 +00:00 CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions.
5
Moyen