PT-2023-14963 · Tecrail · Tecrail Responsive Filemanager
CVE-2022-46604
·
Publicado
2023-02-02
·
Atualizado
2024-09-10
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tecrail Responsive FileManager versions 9.9.5 and below
Description
An issue in Tecrail Responsive FileManager allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leading to arbitrary code execution. This has been observed to be used by threat actors.
Recommendations
For versions 9.9.5 and below, consider disabling the file upload feature until a patch is available to prevent arbitrary code execution. Restrict access to the file extension check mechanism to minimize the risk of exploitation. Avoid using the file upload feature in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tecrail Responsive Filemanager