Skip to main content

Path Traversal: '\UNC\share\name\' (Windows UNC Share)

CVE-2025-32103

Severity Medium
Score 5/10

Summary

CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions.

  • LOW
  • NETWORK
  • LOW
  • CHANGED
  • NONE
  • LOW
  • NONE
  • NONE

CWE-40 - Path Traversal: '\UNC\share\name\' (Windows UNC Share)

An attacker can inject a Windows UNC share ('\\UNC\share\name') into a software system to potentially redirect access to an unintended location or arbitrary file.

References

Advisory Timeline

  • Published