CVE-2021-44076
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in CrushFTP 9. The creation of a new user through the /WebInterface/UserManager/ interface allows an attacker, with access to the administration panel, to perform Stored Cross-Site Scripting (XSS). The payload can be executed in multiple scenarios, for example when the user's page appears in the Most Visited section of the page.
Se ha detectado un problema en CrushFTP 9. La creación de un nuevo usuario mediante la interfaz /WebInterface/UserManager/ permite a un atacante, con acceso al panel de administración, llevar a cabo un ataque de tipo Cross-Site Scripting (XSS) Almacenado. La carga útil puede ser ejecutado en múltiples escenarios, por ejemplo cuando la página del usuario aparece en la sección Most Visited de la página
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-11-19 CVE Reserved
- 2022-09-15 CVE Published
- 2024-04-07 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://labs.nettitude.com/blog/cve-2021-44076-cross-site-scripting-xss-in-crushftp | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.crushftp.com | 2022-09-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Crushftp Search vendor "Crushftp" | Crushftp Search vendor "Crushftp" for product "Crushftp" | >= 9.0.0 < 9.4.0_15 Search vendor "Crushftp" for product "Crushftp" and version " >= 9.0.0 < 9.4.0_15" | - |
Affected
|