CVE-2024-4040

NVD Published Date: April 22, 2024 at 08:15 PM
NVD Last Modified: April 26, 2024 at 03:25 PM
Download Patch
Vulnerability ID
CVE-2024-4040
Severity
CRITICAL
Severity Score
10.0
Summary
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
Metasploit Payload
-
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE ID
CWE-94

Recent Publish

KB890830

CVE-2024-3400

CVE-2024-7023

CVE-2024-7024

CVE-2024-4657

See More ...

See SecOps Solution
in action

Schedule Demo