CVE-2024-4040
EPSS Score
Source: FIRST.org · 2026-05-23CVSS v3.1
Source: VulnerabilityLookup (CIRCL)Description
VulnerabilityLookup (CNA)Affected Products
Attack Intelligence
Exploits & PoC
CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support
Scanner for CVE-2024-4040
is a PoC for CVE-2024-4040 tool for exploiting the SSTI vulnerability in CrushFTP
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote att
Exploit CrushFTP CVE-2024-4040
CVE-2024-4040 PoC
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote att
exploit for CVE-2024-4040
Exploit for CVE-2024-4040 affecting CrushFTP server in all versions before 10.7.1 and 11.1.0 on all platforms
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote att
CVE-2024-4040 PoC
Exploit for CVE-2024-4040 – Authentication bypass in CrushFTP via CrushAuth cookie and AWS-style header spoofing. Stealthy Python PoC with secure toke
A Dockerized setup for running a vulnerable CrushFTP 10 server instance (CVE-2024-4040).