Back

CRITICAL KEV

Unauthenticated arbitrary file read and remote code execution in CrushFTP

Published Apr 22, 2024 ·Due May 1, 2024

Description

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.

Affected products

Remediation

No remediation recorded yet.

References (9)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner directcyber
Published Apr 22, 2024
Updated Oct 21, 2025
Reserved Apr 22, 2024

CISA Vulnrichment

Updated Feb 4, 2025

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner directcyber
Published Apr 22, 2024
Updated Oct 21, 2025
Exploited since Apr 24, 2024

GitHub

No data