Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.
The error classified as CWE-434 (unrestricted upload of file with dangerous type) consists of the lack of proper verification of uploaded files on the application side. An attacker can force the application to download and save a specially crafted file from a malicious (S)FTP server under their control. The file uploaded in this manner can contain an executable payload, which is then executed on the target server.
An attacker without any authentication can gain full control over the server through remote code execution (RCE). This results in potential system compromise, data theft, and the ability to perform lateral movement within the network.
Monsta FTP must be immediately updated to a version newer than 2.11. Details regarding available patches can be found in the official manufacturer's notes at https://www.monstaftp.com/notes/. Until the update is applied, consider restricting network access to the Monsta FTP panel exclusively to trusted IP addresses.
Monsta FTP in version 2.11 and all earlier versions.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMonstaftp Monsta Ftp
APPMonstaftp≤ 2.11
Related vulnerabilities
Dowolne przesyłanie plików w Monsta FTP umożliwiające RCE
SSRF w Monsta FTP v2.10.3 umożliwia nieautoryzowane żądania po stronie serwera
SSRF w Monsta FTP — odczyt plików lokalnych i dostęp do usług zewnętrznych
Monsta FTP — zewnętrzna kontrola ścieżek umożliwiająca RCE
Monsta FTP 2.10.1 or below is prone to a stored cross-site scripting vulnerability in the language setting due...