CVE-2024-4040

EUVD-2024-32605
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
crushftpcrushftp
10.0.0 ≤
𝑥
< 10.7.1
crushftpcrushftp
11.0.0 ≤
𝑥
< 11.1.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
crushftpcrushftp
10.0 ≤
𝑥
< 10.7.1
ADP
crushftpcrushftp
11.0 ≤
𝑥
< 11.1.0
ADP