CrushFTP before 7.8.0 and 8.x before 8.2.0 has an HTTP header vulnerability.
mitre·CWE-93·Published 2017-08-30