CVE-2024-4040
Description
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
Summary dbcve.org
CrushFTP contains a server-side template injection (SSTI) vulnerability in versions prior to 10.7.1 and 11.1.0. This flaw allows unauthenticated attackers to read files outside the VFS sandbox, bypass authentication to obtain administrative privileges, and achieve remote code execution on the server.
Mitigation
Immediately update CrushFTP to version 10.7.1 or 11.1.0 or later. If immediate patching is not possible, restrict network access to the CrushFTP management interfaces and monitor for indicators of compromise.