HomePentest-Tools.com Logo

CrushFTP < 10.5.1 - Unauthenticated Remote Code Execution CVE-2023-43177

Severity
CVSSv3 Score
9.8
Vulnerability description

CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.\n

Risk description

The risk exists that a remote unauthenticated attacker can fully compromise the server to steal confidential information, install ransomware, or pivot to the internal network.

Recommendation

We recommend you to upgrade the affected software to the latest version, which mitigates this vulnerability.

Codename
Not available
Detectable with
Network Scanner
Scan engine
Nuclei
Exploitable with Sniper
No
CVE Published
Nov 18, 2023
Detection added at
Software Type
Not available
Vendor
Not available
Product
Not available