CVE-2024-4040
CVSS V2 None
CVSS V3 None
Description
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
Overview
- CVE ID
- CVE-2024-4040
- Assigner
- directcyber
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-04-22T19:21:46.408Z
- Last Modified Date
- 2024-06-04T17:56:36.470Z
Weakness Enumerations
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-4040 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4040 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-23 22:21:58 | Added to TrackCVE |