CRITICAL

CVE-2024-4040

Crushftp Crushftp 2024-04-22 CVSS v3.1
CVSS
10
KEV

Description

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.

Summary dbcve.org

CrushFTP contains a server-side template injection (SSTI) vulnerability in versions prior to 10.7.1 and 11.1.0. This flaw allows unauthenticated attackers to read files outside the VFS sandbox, bypass authentication to obtain administrative privileges, and achieve remote code execution on the server.

Mitigation

Immediately update CrushFTP to version 10.7.1 or 11.1.0 or later. If immediate patching is not possible, restrict network access to the CrushFTP management interfaces and monitor for indicators of compromise.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-1336
CWE-94 Code Injection

EPSS Score

99.54%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE