S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated May 26, 2024

CVE-2024-4040 Scanner

CVE-2024-4040 scanner - Local File Inclusion (LFI) vulnerability in CrushFTP

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2024-4040
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
CrushFTPby CrushFTP
AFFECTED< 10.7.1SAFE ✓≥ 10.7.1
crushftpby crushftp
AFFECTED< 10.7.1SAFE ✓≥ 10.7.1
crushftpby crushftp
AFFECTED< 11.1.0SAFE ✓≥ 11.1.0
Updated Sep 10, 2026View on NVD →
Detail

CrushFTP is widely used by enterprises and individuals to manage and transfer files securely over the internet. It is favored for its robustness, extensive feature set, and cross-platform compatibility. Administrators use it to handle large volumes of file transfers efficiently. It supports various protocols such as FTP, SFTP, and WebDAV, ensuring flexibility in deployment. CrushFTP's Virtual File System (VFS) offers advanced permissions and access controls to enhance security.

The Local File Inclusion (LFI) vulnerability in CrushFTP allows attackers to access files on the server outside of the designated sandbox. This flaw can be exploited remotely by attackers with low privileges. Successful exploitation can lead to unauthorized access to sensitive data. It poses a critical security risk due to the potential exposure of confidential information.

The vulnerability resides in the VFS Sandbox component of CrushFTP, which fails to properly restrict file access. An attacker can exploit this flaw by sending crafted HTTP requests that include file paths. These requests bypass the sandbox restrictions and access files outside the intended directory. The vulnerability is present in the handling of ZIP file creation commands within the WebInterface. Both authenticated and unauthenticated exploitation paths are possible, depending on the attacker's privileges.

Exploitation of this vulnerability can lead to significant data breaches. Attackers may gain access to system files, configuration files, and other sensitive information. Unauthorized file access can compromise the confidentiality and integrity of data stored on the server. This breach could lead to further attacks, including privilege escalation and remote code execution. The impact can be severe, affecting both organizational operations and reputation.

By using the S4E platform, you can proactively detect and mitigate vulnerabilities like CVE-2024-4040 in your systems. Our platform offers comprehensive scanning capabilities, ensuring that your digital assets are secure from exploitation. Stay ahead of potential threats with timely alerts and detailed vulnerability reports. Benefit from our extensive knowledge base and expert recommendations to enhance your cybersecurity posture. Join us today to safeguard your critical data and maintain robust security across your infrastructure.

References:

Solution Advice
  • Apply the vendor-supplied patch or upgrade to the latest version of CrushFTP to mitigate CVE-2024-4040.
  • Restrict access to the CrushFTP WebInterface to trusted IP addresses only.
  • Implement strong access controls and regularly review user permissions.
  • Monitor and log file access activities to detect any unusual or unauthorized actions.
  • Conduct regular security audits and vulnerability assessments to ensure ongoing protection.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-4040 scanner - Local File Inclusion (LFI) vulnerability in CrushFTP | S4E