Exploit for #VU88869 External Control of File Name or Path in CrushFTP


Published: 2024-04-26 | Updated: 2024-05-13

Vulnerability identifier: #VU88869

Vulnerability risk: High

CVSSv3.1: 6.2 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:H/RL:O/RC:C]

CVE-ID: CVE-2024-4040

CWE-ID: CWE-73

Exploitation vector: Network

Exploits in database: 6

Impact: Information disclosure

Vulnerable software:
CrushFTP
Server applications / File servers (FTP/HTTP)

Vendor: