
CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin sessions.
CWE-79 — Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
As noted in the vendor changelog ( https://crushftp.com/version11_build.html ) Versions 11.3.7_57 and later are not affected.
_57:login URL fix and session kicking fix, and a minor HTMLi for reports: CVE-2025-63420
A stored HTMLi vulnerability in the CrushFTP Admin Panel (Reports / 'Who Created Folder') allows authenticated attackers with permissions to create folders to inject malicious HTML codes.
<h1>HACKED</h1>test


