CVE-2024-4040 – VFS Sandbox Escape in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms …

Vuln ID: CVE-2024-4040

Published:  2024-04-22  20:15:07.803

Description: VFS Sandbox Escape in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows remote attackers with low privileges to read files from the filesystem outside of VFS Sandbox.

Base Score: 7.7 – HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Source: NVD.NIST.GOV

 


Date:

Categorie(s):

Tag(s):