CVE-2018-18288: Medium severity crushftp vulnerability
Published Dec 26, 2019
·Updated
CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.
Affected Software
1 affected component
CrushFTP Crushftp<=8.3.0
Event History
Dec 26, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2018-18288?
CVE-2018-18288 is a vulnerability in CrushFTP through 8.3.0 that allows for credentials theft via URL redirection.
2
How severe is CVE-2018-18288?
CVE-2018-18288 has a severity rating of 6.1 (medium).
3
How does CVE-2018-18288 work?
CVE-2018-18288 allows an attacker to steal user credentials by tricking them into visiting a malicious website with a specially crafted URL that redirects to the attacker's site.
4
Is my version of CrushFTP affected?
If you are using CrushFTP up to version 8.3.0, then you are vulnerable to CVE-2018-18288.
5
How can I protect myself from CVE-2018-18288?
To protect yourself from CVE-2018-18288, update CrushFTP to a version higher than 8.3.0 where the vulnerability has been patched.