CrushFTP
Last updated
Last updated
Proof of Concept for CVE-2025-31161 / CVE-2025-2825
This POC will exploit the authbypass vulnerability to create a new user account with Admin level permissions. The Auth Bypass requires the username (target_user) of an existing user on the CrushFTP server. The default is set to crushadmin