CVE-2024-4040

CVSS v3.1 10 (Critical)
100% Progress
EPSS 96.54 % (100th)
96.54% Progress
Affected Products 1
Advisories 1
NVD Status Analyzed

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.

Weaknesses
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
CWE-94
Improper Control of Generation of Code ('Code Injection')
CVE Status
PUBLISHED
NVD Status
Analyzed
CNA
DirectCyber
Published Date
2024-04-22 20:15:07
(5 months ago)
Updated Date
2024-04-26 15:25:47
(4 months ago)
CrushFTP VFS Sandbox Escape Vulnerability (CISA - Known Exploited Vulnerabilities Catalog)
Description
CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS).
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known to be Used in Ransomware Campaigns
Unknown
Notes
https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update&version=34; https://nvd.nist.gov/vuln/detail/CVE-2024-4040
Vendor
CrushFTP
Product
CrushFTP
In CISA Catalog from
2024-04-24
(4 months ago)
Due Date
2024-05-01
(4 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Crushftp from 10.0.0 version and prior 10.7.1 version cpe:2.3:a:crushftp:crushftp >= 10.0.0 < 10.7.1
  Crushftp from 11.0.0 version and prior 11.1.0 version cpe:2.3:a:crushftp:crushftp >= 11.0.0 < 11.1.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...