Medium severity5.0NVD Advisory· Published Apr 15, 2025· Updated Jun 17, 2026
CVE-2025-32103
CVE-2025-32103
Description
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
4- packetstorm.news/files/id/190460/nvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2025/Apr/17nvdExploitMailing ListThird Party Advisory
- www.crushftp.comnvdProduct
- seclists.org/fulldisclosure/2025/Apr/17nvd
News mentions
0No linked articles in our index yet.