peter bassill · operator
$ cve CVE-2024-4040 JSON

CVE-2024-4040 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 99.5% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2024-05-01.

Description

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.54% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-1336
On CISA KEVyes — remediate by 2024-05-01
Public exploitnone known
Published2024-04-22
Last modified2026-06-17

CISA KEV

NameCrushFTP VFS Sandbox Escape Vulnerability
Added2024-04-24
Due2024-05-01
Vendor / productCrushFTP / CrushFTP
Ransomware usenone reported

Affected (1)

VendorProduct
crushftpcrushftp

References

→ the Explorer  ·  watch your stack  ·  NVD