CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions.
CVE ID: CVE-2025-32103
Vendor: n/a
Product: n/a
EPSS Score: 0.08% (probability of being exploited)
EPSS Percentile: 24.86% (scored less or equal to compared to others)
EPSS Date: 2025-04-21 (when was this score calculated)