Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Nov 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 07 Nov 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server. | |
| Title | Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-11-07T13:51:33.738Z
Updated: 2025-11-07T19:20:52.087Z
Reserved: 2025-04-15T19:15:22.582Z
Link: CVE-2025-34299
Updated: 2025-11-07T19:20:49.066Z
Status : Received
Published: 2025-11-07T14:15:49.920
Modified: 2025-11-07T14:15:49.920
Link: CVE-2025-34299
No data.