Loading
Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48. The Web-Based Server has a feature where users can share files, the feature reflects the filename to an emailbody field with no sanitations leading to HTML Injection.
Use CWE-79, Crushftp vendor hub and Crushftp product page to widen CVE-2025-63419 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-31161, CVE-2024-4040 and CVE-2025-54309 for nearby disclosures in the same product family.