CVE-2023-43177: CrushFTP
Critical severity, CVSS 9.8. EPSS: 81.8% chance of exploitation in the next 30 days.
CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.
Affected products
- CrushFTP CrushFTP: before 10.5.2 (fixed in 10.5.2)
Published 2023-11-18. Last modified 2026-06-17.