Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Donot-Wong

#30539de 53,634
8.6CVSS total
Vulnerabilidades · 1
PT-2018-14701
8.6
2018-10-31
Tecrail · Tecrail Responsive Filemanager · CVE-2018-18867
**Name of the Vulnerable Software and Affected Versions** tecrail Responsive FileManager version 9.13.4 **Description** A Server-Side Request Forgery (SSRF) issue was discovered in the software. The issue is related to an incomplete fix for a previous problem and can be exploited via the "url" parameter in the "upload.php" endpoint. **Recommendations** For version 9.13.4, as a temporary workaround, consider restricting access to the "upload.php" endpoint until a patch is available. Avoid using the `url` parameter in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.