I recreated the CrushFTP CVE-2024-4040 exploit

Опубликовано: 28 Июнь 2026
на канале: Hack the Clown
2,281
151

This video will show you how to create an exploit for CVE-2024-2020 (Crush FTP SSTI) to demonstrate the vulnerability.

We will only focus on SSTI + Arbitrary File Read since Remote code execution attack may require CrushFTP license in order to use the CrushTask plugin (allows exeucution of custom scripts).

Do note that this is for education purposes only and MUST NOT be used for malicious intent.

// Tags

#ethicalhacking #python #crushftp #cve-2024-2020 #ssti

// Chapters

0:00 - Intro
1:02 - Setting up vulnerable app
3:17 - Exploring crushftp admin page
4:33 - Creating the base script
8:02 - URL builder function
9:47 - Initializing the class
10:18 - Getting the anonymous cookie
12:36 - Quick analysis on the vulnerability
13:48 - Reading the file
16:05 - Adding a scanner
18:52 - Interactive mode
21:16 - Some python trick :)

// Links

Vulnerability Analysis from Attacker KB - https://attackerkb.com/topics/20oYjlm...