PoC Index

CVE-2024-4040

KEVCRITICAL 10.0EPSS 99.5%

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.

CVSS v3.1
10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
99.54% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2024-04-24
Nuclei
critical
Published
2024-04-22
Updated
2025-10-21

Proof-of-concept exploits (24)

Nuclei templates (1)

Metasploit modules (1)

References

Related