Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-63420 — Proof-of-concept for CVE-2025-63420: stored HTML injection in CrushFTP Admin Panel Reports. Includes reproduction steps, CVSS scoring, and payload examples for authenticated XSS testing. | Kitploit
Tools/GitHubGitHub/hossainshadat/cve-2025-63420
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingLearning & Education
GitHubhossainshadat/cve-2025-63420

CVE-2025-63420

Proof-of-concept for CVE-2025-63420: stored HTML injection in CrushFTP Admin Panel Reports. Includes reproduction steps, CVSS scoring, and payload examples for authenticated XSS testing.

View Repository
10 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-63420

CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin sessions.

CWE

CWE-79 — Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)

CVSS v3.1 Base Score: 4.1 (Medium)

AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N

Resolved in

As noted in the vendor changelog ( https://crushftp.com/version11_build.html ) Versions 11.3.7_57 and later are not affected.

_57:login URL fix and session kicking fix, and a minor HTMLi for reports: CVE-2025-63420

Summary

A stored HTMLi vulnerability in the CrushFTP Admin Panel (Reports / 'Who Created Folder') allows authenticated attackers with permissions to create folders to inject malicious HTML codes.

Steps to reproduce

  1. Navigate to http://127.0.0.1:8080/
  2. Create a new Folder with the following payload:
<h1>HACKED</h1>test

CreatingFolder1 CreatingFolder2

  1. Navigate to http://127.0.0.1:8080/WebInterface/admin/index.html, Click on "Reports" and select "Who Created Folder": SelecitingReport
  2. Click on "Run Report"
  3. Wait for the report to load, after the report is loaded, scroll down and observe the HTMLi: XSS
  4. For some UI Reasons, you might wanna create 2 folders within the same payload for the HTMLi to show.
Download Tool