CVE-2025-32103: Path Traversal
Published Apr 15, 2025
·Updated
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions.
Affected Software
2 affected components
CrushFTP Crushftp>=9.0<10.8.4, >=11.0<=11.3.1
CrushFTP Crushftp>=9.0.0<=11.3.1
Event History
Apr 15, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-32103?
CVE-2025-32103 is classified as a high-severity vulnerability due to its ability to exploit directory traversal in CrushFTP.
2
How do I fix CVE-2025-32103?
To fix CVE-2025-32103, you should upgrade to CrushFTP version 10.8.5 or 11.3.2 or later.
3
What products are affected by CVE-2025-32103?
CVE-2025-32103 affects CrushFTP versions 9.x through 10.8.4 and 11.x through 11.3.1.
4
What is the impact of CVE-2025-32103?
The impact of CVE-2025-32103 includes unauthorized access to files through directory traversal exploiting SMB UNC share pathnames.
5
Is CVE-2025-32103 a zero-day vulnerability?
CVE-2025-32103 is not a zero-day vulnerability but it poses a significant risk until patched.