CVE-2024-4040criticalunder attackCWE-1336

CVE-2024-4040: critical vulnerability in CrushFTP

Unauthenticated arbitrary file read and remote code execution in CrushFTP

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 100%
from disclosure to weapon1 days
Published on NVDApr 22
1st PoC+1d
CISA KEV+2d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
36 public exploit(s)
Action required by CISAfederal deadline: 2024-05-01

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

In short

CrushFTP has a critical flaw that lets attackers without any login credentials read files from the server, take over as administrator, and run harmful code—all remotely and without authentication.

Technical detail

A server-side template injection vulnerability in CrushFTP versions before 10.7.1 and 11.1.0 allows unauthenticated remote attackers to execute arbitrary code and bypass authentication mechanisms. The vulnerability enables unauthorized file system access outside the VFS sandbox and elevation to administrative privileges, affecting all platforms.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
CrushFTP · CrushFTP
public PoCs found — 36
githubgithub.com/Stuub/CVE-2024-4040-SSTI-LFI-PoC★ 63cve_referencegithub.com/airbus-cert/CVE-2024-4040★ 52githubgithub.com/rbih-boulanouar/CVE-2024-4040★ 14githubgithub.com/geniuszly/GenCrushSSTIExploit★ 8githubgithub.com/gotr00t0day/CVE-2024-4040★ 7githubgithub.com/dhammerg/CVE-2024-4040★ 5githubgithub.com/jakabakos/CVE-2024-4040-CrushFTP-File-Read-vulnerability★ 4githubgithub.com/entroychang/CVE-2024-4040★ 3githubgithub.com/rahisec/CVE-2024-4040★ 0githubgithub.com/ill-deed/CrushFTP-CVE-2024-4040-illdeed★ 0githubgithub.com/Sidjaz/CrushFTP-CVE-2024-4040-Proof-of-Concept★ 0githubgithub.com/juanorts/CrushFTP10-Docker-CVE-2024-4040★ 0githubgithub.com/cthhhhhh/CrushFTP-SSTI-LFI-Proof-of-Concept★ 0githubgithub.com/Mufti22/CVE-2024-4040★ 0githubgithub.com/0xN7y/CVE-2024-4040★ 0githubgithub.com/Praison001/CVE-2024-4040-CrushFTP-server★ 0githubgithub.com/1ncendium/CVE-2024-4040★ 0githubgithub.com/olebris/CVE-2024-4040★ 0githubgithub.com/safeer-accuknox/CrushFTP-cve-2024-4040-poc★ 0vulncheckvulncheck.com/xdb/247af1523302unverifiedvulncheckvulncheck.com/xdb/1a53f981a558unverifiedvulncheckvulncheck.com/xdb/b40b6bf3d5a6unverifiedvulncheckvulncheck.com/xdb/40ea0e9b601dunverifiedvulncheckvulncheck.com/xdb/d683df1ebca9unverifiedvulncheckvulncheck.com/xdb/c046e180c9e7unverifiedvulncheckvulncheck.com/xdb/2655831cd2edunverifiedvulncheckvulncheck.com/xdb/c76b89de33efunverifiedvulncheckvulncheck.com/xdb/eeeb1a30c8c2unverifiedvulncheckvulncheck.com/xdb/458c6db39e2eunverifiedvulncheckvulncheck.com/xdb/e71d60507f5dunverifiedvulncheckvulncheck.com/xdb/6e43a515753dunverifiedvulncheckvulncheck.com/xdb/49d5d24a6094unverifiedvulncheckvulncheck.com/xdb/896af97e3f84unverifiedvulncheckvulncheck.com/xdb/046e8f9ffb52unverifiedvulncheckvulncheck.com/xdb/33874f45fc53unverifiedvulncheckvulncheck.com/xdb/df5498fd3264unverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.