Vulnerabilities > Monstaftp

DATE CVE VULNERABILITY TITLE RISK
2022-06-09 CVE-2022-31827 Server-Side Request Forgery (SSRF) vulnerability in Monstaftp 2.10.3
MonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at HTTPFetcher.php.
network
low complexity
monstaftp CWE-918
critical
9.1
2022-04-26 CVE-2022-27468 Unrestricted Upload of File with Dangerous Type vulnerability in Monstaftp Monsta FTP 2.10.3
Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to the web server.
network
low complexity
monstaftp CWE-434
critical
9.8
2022-04-26 CVE-2022-27469 Server-Side Request Forgery (SSRF) vulnerability in Monstaftp Monsta FTP 2.10.3
Monstaftp v2.10.3 was discovered to allow attackers to execute Server-Side Request Forgery (SSRF).
network
low complexity
monstaftp CWE-918
critical
9.8
2020-07-01 CVE-2020-14057 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Monstaftp Monsta FTP
Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations.
network
low complexity
monstaftp CWE-610
critical
9.8
2020-07-01 CVE-2020-14056 Server-Side Request Forgery (SSRF) vulnerability in Monstaftp Monsta FTP
Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality.
network
low complexity
monstaftp CWE-918
critical
9.8
2020-07-01 CVE-2020-14055 Cross-site Scripting vulnerability in Monstaftp Monsta FTP
Monsta FTP 2.10.1 or below is prone to a stored cross-site scripting vulnerability in the language setting due to insufficient output encoding.
network
low complexity
monstaftp CWE-79
6.1