4.8
CVSSv3

CVE-2021-44076

Published: 15/09/2022 Updated: 17/09/2022
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 0

Vulnerability Summary

An issue exists in CrushFTP 9. The creation of a new user through the /WebInterface/UserManager/ interface allows an attacker, with access to the administration panel, to perform Stored Cross-Site Scripting (XSS). The payload can be executed in multiple scenarios, for example when the user's page appears in the Most Visited section of the page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

crushftp crushftp