CVE-2024-4040

EUVD-2024-32605
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
directcyberCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
crushftpcrushftp
10.7.1 <
𝑥
< 10.7.1
crushftpcrushftp
11.1.0 <
𝑥
< 11.1.0
crushftpcrushftp
10.0.0 ≤
𝑥
< 10.7.1
crushftpcrushftp
11.0.0 ≤
𝑥
< 11.1.0
𝑥
= Vulnerable software versions