{ "id": "CVE-2023-43177", "sourceIdentifier": "cve@mitre.org", "published": "2023-11-18T00:15:07.073", "lastModified": "2023-11-18T04:19:44.183", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes." } ], "metrics": {}, "references": [ { "url": "https://convergetp.com/2023/11/16/crushftp-zero-day-cve-2023-43177-discovered/", "source": "cve@mitre.org" }, { "url": "https://github.com/the-emmons/CVE-Disclosures/blob/main/Pending/CrushFTP-2023-1.md", "source": "cve@mitre.org" } ] }