Loading
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
Use CWE-1336, Crushftp vendor hub and Crushftp product page to widen CVE-2024-4040 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-31161, CVE-2025-54309 and CVE-2024-53552 for nearby disclosures in the same product family.