EUVD-2024-32605
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 24 Apr 2024. Evidence sources: cisa_kev.
- ENISA score
- 9.8 · CVSS 3.1
- Advisory evidence
- 1 linked advisory record
