Critical severity9.8CISA KEVNVD Advisory· Published Apr 22, 2024· Updated Jun 17, 2026
CVE-2024-4040
CVE-2024-4040
Description
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
7- www.crushftp.com/crush10wiki/Wiki.jspnvdPatchVendor Advisory
- www.crushftp.com/crush11wiki/Wiki.jspnvdPatchVendor Advisory
- www.reddit.com/r/cybersecurity/comments/1c850i2/all_versions_of_crush_ftp_are_vulnerable/nvdIssue TrackingPatch
- www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/nvdExploitIssue Tracking
- www.bleepingcomputer.com/news/security/crushftp-warns-users-to-patch-exploited-zero-day-immediately/nvdPress/Media CoverageThird Party Advisory
- www.rapid7.com/blog/post/2024/04/23/etr-unauthenticated-crushftp-zero-day-enables-complete-server-compromise/nvdThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.