CVE-2023-43177 is a critical vulnerability in CrushFTP affecting versions prior to 10.5.2. The flaw has been described as an improper control over modification of dynamically determined object attributes, indicating a mass-assignment style weakness in server-side handling of attacker-supplied object properties. Public reporting also states that successful exploitation can allow an unauthenticated attacker to access files stored on the CrushFTP server, execute code remotely, and obtain plaintext passwords. A public proof-of-concept exploit was disclosed, increasing the likelihood of opportunistic exploitation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting CVE-2023-43177, a critical unauthenticated remote code execution vulnerability in CrushFTP versions prior to 10.5.1. The exploit leverages improper handling of session properties via crafted HTTP headers to hijack user sessions, escalate privileges, and ultimately achieve remote code execution by abusing dynamic SQL driver loading. The module is highly weaponized, supporting multiple payloads (Java meterpreter, Linux/Windows binaries), and automates the process of privilege escalation, admin account creation, code execution, and cleanup. The main attack vector is network-based, exploiting the CrushFTP web interface (default port 8080). The code is structured as a standard Metasploit exploit module, with clear separation of initialization, exploitation logic, and cleanup routines. No hardcoded IPs or domains are present, but the module interacts with the web interface endpoints of the target server.
This repository contains a single Python exploit script (CVE-2023-43177.py) and a brief README. The exploit targets CrushFTP servers (versions <=10.5.1) and leverages a vulnerability (CVE-2023-43177) to achieve remote code execution. The script operates by first obtaining an anonymous session, then stealing the 'sessions.obj' file to enumerate and hijack valid user sessions. If an admin session is found, the script can escalate privileges and execute arbitrary commands on the server. The exploit interacts with the CrushFTP web interface over HTTPS, using endpoints such as '/WebInterface/function/'. The code is operational, providing both session hijacking and RCE capabilities, and is intended for use against vulnerable, internet-accessible CrushFTP instances. The repository is well-structured for exploitation, with the main logic contained in a single, comprehensive Python file.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A specific vulnerability referenced only as a Nuclei template filename update in a pull request; no technical details are provided in the content.
A prior CrushFTP protocol-related vulnerability referenced in the vendor security history.
A critical remote code execution vulnerability in CrushFTP for which a proof-of-concept exploit was released.
A critical CrushFTP vulnerability that can allow unauthenticated access to server files, remote code execution, and disclosure of plain-text passwords.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.