← Back

CVE-2024-4040

Published: Apr 22, 2024Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
10.0
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 6.0
Source: NVD

Description

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.

Affected (2)

Products: Crushftp: Crushftp
1 product
Crushftp
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Crushftp
From 10.0.0 to 10.7.1
From 11.0.0 to 11.1.0

References (15)

Source: 430a6cef-dc26-47e3-9fa8-52fb7f19644e
ExploitThird Party Advisory
Source: 430a6cef-dc26-47e3-9fa8-52fb7f19644e
Press/Media CoverageThird Party Advisory
Source: 430a6cef-dc26-47e3-9fa8-52fb7f19644e
PatchVendor Advisory
Source: 430a6cef-dc26-47e3-9fa8-52fb7f19644e
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Press/Media CoverageThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.