Cross Site Scripting Vulnerability in CrushFTP Products
CVE-2024-22910

6.1MEDIUM

Key Information:

Vendor
CrushFTP
Vendor
CVE Published:
14 May 2024

Summary

A cross site scripting vulnerability has been identified in CrushFTP versions 10.6.0 and 10.5.5. This security flaw allows attackers to execute arbitrary code by sending specially crafted payloads, potentially compromising the integrity of the application and affecting user security. Users are advised to review their current configurations and consider upgrading to the latest version to mitigate any risks associated with this vulnerability.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.