CVE-2024-4040

CVSS V2 None CVSS V3 None
Description
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
Overview
  • CVE ID
  • CVE-2024-4040
  • Assigner
  • directcyber
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-04-22T19:21:46.408Z
  • Last Modified Date
  • 2024-06-04T17:56:36.470Z
History
Created Old Value New Value Data Type Notes
2024-06-23 22:21:58 Added to TrackCVE