Executive brief
A server-side template injection (SSTI) vulnerability in CrushFTP allows unauthenticated remote attackers to escape the Virtual File System (VFS) sandbox. This enables attackers to read arbitrary files from the host filesystem, bypass authentication for administrative access, and execute remote code.
Affected products
- CrushFTP CrushFTP versions before 10.7.1 and 11.1.0
Timeline
- 2024-04-24: disclosed
- 2024-04-24: kev added: Added to CISA KEV catalog
- 2024-04-24: patched: Fixed in versions 10.7.1 and 11.1.0