CVE-2024-11986: Crushftp, Llc CrushFTP
Critical severity, CVSS 9.6. EPSS: 0.6% chance of exploitation in the next 30 days.
Improper input handling in the 'Host Header' allows an unauthenticated attacker to store a payload in web application logs. When an Administrator views the logs using the application's standard functionality, it enables the execution of the payload, resulting in Stored XSS or 'Cross-Site Scripting'.
Affected products
- Crushftp, Llc CrushFTP: from 10.0.0, before 10.8.2 (fixed in 10.8.2); from 11.0.0, before 11.2.1 (fixed in 11.2.1)
Published 2024-12-13. Last modified 2026-06-17.