CVE-2025-31161 | CrushFTP up to 10.8.3/11.3.0 HTTP Component login_user_pass authentication bypass
A vulnerability classified as critical has been found in CrushFTP up to 10.8.3/11.3.0. This affects the function login_user_pass of the component HTTP Component. The manipulation leads to authentication bypass by primary weakness.
This vulnerability is uniquely identified as CVE-2025-31161. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.