CVE-2025-63420 UNKNOWN

CVE-2025-63420

Published: 2025-11-07

Description

A stored cross-site scripting (XSS) vulnerability in the CrushFTP 11.3.7_50 Admin Panel (Reports / 'Who Created Folder') allows authenticated attackers with permissions to create folders to inject malicious HTML/JavaScript.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…