Responsive Filemanager · Responsive Filemanager · CVE-2018-14728
**Name of the Vulnerable Software and Affected Versions**
Responsive FileManager version 9.13.1
**Description**
The issue allows for Server-Side Request Forgery (SSRF) via the `url` parameter in the upload.php file.
**Recommendations**
For Responsive FileManager version 9.13.1, consider restricting access to the upload.php file or the `url` parameter to minimize the risk of exploitation. As a temporary workaround, avoid using the `url` parameter in the upload.php file until a patch is available.