CVE-2024-11986: Stored XSS in CrushFTP
Improper input handling in the 'Host Header' allows an unauthenticated attacker to store a payload in web application logs. When an Administrator views the logs using the application's standard functionality, it enables the execution of the payload, resulting in Stored XSS or 'Cross-Site Scripting'.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11986?
CVE-2024-11986 has a critical severity level due to the potential for stored XSS attacks.
How do I fix CVE-2024-11986?
To fix CVE-2024-11986, ensure you update to the latest version of CrushFTP that addresses this vulnerability.
What systems are affected by CVE-2024-11986?
CVE-2024-11986 specifically affects CrushFTP applications.
What type of attack does CVE-2024-11986 enable?
CVE-2024-11986 enables stored cross-site scripting (XSS) attacks through improper input handling in the Host Header.
Can an attacker exploit CVE-2024-11986 without authentication?
Yes, an unauthenticated attacker can exploit CVE-2024-11986 by storing malicious payloads in web application logs.