CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.
References
| Link | Resource |
|---|---|
| https://www.crushftp.com/version8_build.html | Release Notes Vendor Advisory |
| https://il.linkedin.com/in/yuval-orenstein-9a6698106/ | Third Party Advisory |
Configurations
Information
Published : 2019-12-26 01:15
Updated : 2020-01-03 15:03
NVD link : CVE-2018-18288
Mitre link : CVE-2018-18288
JSON object : View
Products Affected
crushftp
- crushftp
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
