Redirect Vulnerability in CrushFTP by CrushFTP, Inc.
CVE-2017-14038

6.1MEDIUM

Key Information:

Vendor

Crushftp

Status
Vendor
CVE Published:
30 August 2017

What is CVE-2017-14038?

CrushFTP versions prior to 7.8.0 and 8.x before 8.2.0 are affected by a redirection vulnerability that could allow an attacker to redirect users to unauthorized locations. This security issue may enable phishing attempts or unauthorized access by directing users to potentially harmful sites.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.
CVE-2017-14038 : Redirect Vulnerability in CrushFTP by CrushFTP, Inc.