CVE-2024-11986: Crushftp, Llc CrushFTP

Critical severity, CVSS 9.6. EPSS: 0.6% chance of exploitation in the next 30 days.

Improper input handling in the 'Host Header' allows an unauthenticated attacker to store a payload in web application logs. When an Administrator views the logs using the application's standard functionality, it enables the execution of the payload, resulting in Stored XSS or 'Cross-Site Scripting'.

Affected products

  • Crushftp, Llc CrushFTP: from 10.0.0, before 10.8.2 (fixed in 10.8.2); from 11.0.0, before 11.2.1 (fixed in 11.2.1)

Published 2024-12-13. Last modified 2026-06-17.