First published: Wed Aug 30 2017(Updated: )
CrushFTP 8.x before 8.2.0 has a serialization vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CrushFTP | =8.0.2 | |
CrushFTP | =8.0.3 | |
CrushFTP | =8.0.4 | |
CrushFTP | =8.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14035 affects CrushFTP versions 8.0.2, 8.0.3, 8.0.4, and 8.1.0.
CVE-2017-14035 is a serialization vulnerability in CrushFTP 8.x before 8.2.0.
CVE-2017-14035 has been classified with a moderate severity level due to the potential for exploitation.
To fix CVE-2017-14035, upgrade to CrushFTP version 8.2.0 or later.
Exploitation of CVE-2017-14035 could allow an attacker to manipulate serialized data, leading to remote code execution.