Monsta Monsta FTP是新西兰Monsta公司的一款文件传输服务器软件。 Monsta FTP 2.14.5之前版本存在服务端请求伪造漏洞,该漏洞源于isBlockedIP()函数IP黑名单检查不完整,未能检测IPv4映射IPv6地址中的嵌入式IPv4地址,导致服务端请求伪造。未经验证的攻击者可获取CSRF令牌并提交fetchRemoteFile请求,使服务器向内部服务发起HTTP请求并将响应写入攻击者控制的FTP目标,从而获取云实例元数据凭据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Monsta Limited of New Zealand | Monsta FTP | < 2.14.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Monsta Limited of New Zealand | Monsta FTP | 0 ~ 2.14.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an incomplete IP blocklist check in the isBlockedIP() function, which fails to detect embedded IPv4 addresses within IPv4-mapped IPv6 addresses. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-60105.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet