CVE-2024-4040

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.

Scoring

Severity
CRITICAL
CVSS base score
9.8
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS probability
99.54%
CISA KEV
Known exploited vulnerability
CWE
CWE-1336
Published
2024-04-22
Last modified
2025-10-21

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs