Description
CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.
Remediation
References
Related Vulnerabilities
Drupal Core 7.x Security Bypass (7.0 - 7.68)
WordPress URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-10100)
WordPress 3.7.x Multiple Vulnerabilities (3.7 - 3.7.17)
WordPress Plugin WP-Spreadshirt-Gallery Cross-Site Scripting (1.3)
WordPress Plugin Ivory Search-WordPress Search Unspecified Vulnerability (5.4.3)