Описание
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
Ссылки
- ExploitThird Party Advisory
- Press/Media CoverageThird Party Advisory
- PatchVendor Advisory
- PatchVendor Advisory
- Third Party Advisory
- ExploitIssue Tracking
- Issue TrackingPatch
- ExploitThird Party Advisory
- Press/Media CoverageThird Party Advisory
- PatchVendor Advisory
- PatchVendor Advisory
- Third Party Advisory
- ExploitIssue Tracking
- Issue TrackingPatch
- US Government Resource
Уязвимые конфигурации
Одно из
EPSS
9.8 Critical
CVSS3
10 Critical
CVSS3
Дефекты
Связанные уязвимости
VFS Sandbox Escape in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows remote attackers with low privileges to read files from the filesystem outside of VFS Sandbox.
Уязвимость веб-интерфейса кроссплатформенного FTP-сервера CrushFTP, позволяющая нарушителю выйти из виртуальной файловой системы (VFS) и получить доступ к системным файлам
EPSS
9.8 Critical
CVSS3
10 Critical
CVSS3