Description
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
Exploits (22)
nomisec
WORKING POC
60 stars
by Stuub · infoleak
https://github.com/Stuub/CVE-2024-4040-SSTI-LFI-PoC
nomisec
WORKING POC
13 stars
by rbih-boulanouar · infoleak
https://github.com/rbih-boulanouar/CVE-2024-4040
nomisec
WORKING POC
8 stars
by geniuszly · infoleak
https://github.com/geniuszly/GenCrushSSTIExploit
nomisec
WORKING POC
3 stars
by jakabakos · infoleak
https://github.com/jakabakos/CVE-2024-4040-CrushFTP-File-Read-vulnerability
github
SCANNER
2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2024/CVE-2024-4040
nomisec
SCANNER
1 stars
by tucommenceapousser · poc
https://github.com/tucommenceapousser/CVE-2024-4040-Scanner
nomisec
WORKING POC
by safeer-accuknox · remote
https://github.com/safeer-accuknox/CrushFTP-cve-2024-4040-poc
nomisec
WORKING POC
by Praison001 · infoleak
https://github.com/Praison001/CVE-2024-4040-CrushFTP-server
metasploit
WORKING POC
by remmons-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/crushftp_fileread_cve_2024_4040.rb
Nuclei Templates (1)
CrushFTP VFS - Sandbox Escape LFR
CRITICALVERIFIEDby DhiyaneshDK,pussycat0x
Shodan:
html:"CrushFTP" || http.html:"crushftp"
FOFA:
body="crushftp"
References (8)
Scores
CVSS v3
9.8
EPSS
0.9443
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Lab Environment
COMMUNITY
Community Lab
+18 more repos
Details
CISA KEV
2024-04-24
VulnCheck KEV
2024-04-19
InTheWild.io
2024-04-24
ENISA EUVD
EUVD-2024-32605
Ransomware Use
Confirmed
CWE
CWE-1336
CWE-94
Status
published
Products (1)
crushftp/crushftp
10.0.0 - 10.7.1
Published
Apr 22, 2024
KEV Added
Apr 24, 2024
Tracked Since
Feb 18, 2026