CVE-2024-4040

CVSS v3 10 (Critical)
EPSS 96.61 % (100th)
Affected Products 1
Advisories 1

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.

Weaknesses
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
CWE-94
Improper Control of Generation of Code ('Code Injection')
CNA
430a6cef-dc26-47e3-9fa8-52fb7f19644e
Published Date
2024-04-22 20:15:07
(3 months ago)
Updated Date
2024-04-26 15:25:47
(3 months ago)
CrushFTP VFS Sandbox Escape Vulnerability (CISA - Known Exploited Vulnerabilities Catalog)
Description
CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS).
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known to be Used in Ransomware Campaigns
Unknown
Notes
https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update&version=34
Vendor
CrushFTP
Product
CrushFTP
In CISA Catalog from
2024-04-24
(3 months ago)
Due Date
2024-05-01
(2 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Crushftp from 10.0.0 version and prior 10.7.1 version cpe:2.3:a:crushftp:crushftp >= 10.0.0 < 10.7.1
  Crushftp from 11.0.0 version and prior 11.1.0 version cpe:2.3:a:crushftp:crushftp >= 11.0.0 < 11.1.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...