National Cyber Warfare Foundation (NCWF) Forums


CrushFTP Vulnerability Exploited in Wild to Execute Remote Code


0 user ratings
2024-05-08 12:40:40
milo
Red Team (CNA)

 - archive -- 

A critical vulnerability in CrushFTP, identified as CVE-2024-4040, has been actively exploited in the wild. It allows attackers to perform unauthenticated remote code execution on vulnerable servers. This severe security flaw affects versions of CrushFTP before 10.7.1 and 11.1.0, enabling attackers to bypass the Virtual File System (VFS) sandbox, gain administrative privileges, and potentially access […]


The post CrushFTP Vulnerability Exploited in Wild to Execute Remote Code appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.



Free Webinar : Live API Attack Simulation


94% of organizations experience security problems in production APIs, and one in five suffers a data breach. As a result, cyber-attacks on APIs increased from 35% in 2022 to 46% in 2023, and this trend continues to rise:


Key Takeaways:



  • An exploit of OWASP API Top 10 vulnerability

  • A brute force ATO (Account Takeover) attack on API

  • A DDoS attack on an API

  • Positive security model automation to prevent API attacks


Start protecting your APIs from hackers




Source: gbHackers
Source Link: https://gbhackers.com/crushftp-vulnerability-exploited/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2024 - National Cyber Warfare Foundation - All rights reserved worldwide.