'; } else{ echo ''; } echo '
|
|||
Release Date:2025/9/15
Rule Name:CVE-2024-4040: CrushFTP Server Side Template Injection Vulnerability
Severity:critical
CVE ID:CVE-2024-4040
Descripiton:
|
CrushFTP is a file transfer server software that supports multiple protocols and security features and is widely used for enterprise and personal file transfer and management needs. A server side template injection vulnerability in CrushFTP in all versions prior to 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote malicious users to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
Other reference:None
Solution:
|
Update vendor patches.