CVE-2020-14056: Monstaftp Monsta FTP
Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.
Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. This allows attackers to read arbitrary local files and interact with arbitrary third-party services.
Affected products
- Monstaftp Monsta FTP: up to and including 2.10.1
Published 2020-07-01. Last modified 2026-06-17.