CVE-2025-34299
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-11-07
Last updated on: 2025-12-10
Assigner: VulnCheck
Description
Description
Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| monstaftp | monsta_ftp | to 2.11 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-434 | The product allows the upload or transfer of dangerous file types that are automatically processed within its environment. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
Monsta FTP versions 2.11 and earlier have a security flaw that allows attackers to upload arbitrary files without authentication. By uploading a specially crafted file from a malicious (S)FTP server, attackers can execute arbitrary code on the affected system.
How can this vulnerability impact me? :
This vulnerability can lead to unauthorized code execution on your system, potentially allowing attackers to take control, compromise data integrity, disrupt services, or use the system as a foothold for further attacks.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70