PT-2020-3996 · Unknown · Responsive Filemanager
Published
2020-03-14
·
Updated
2023-03-07
·
CVE-2020-10567
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Responsive Filemanager versions through 9.14.0
Description:
An issue was discovered in the ajax calls.php file, specifically in the save img action, where the
name parameter lacks validation of the sent extension. This allows for the execution of PHP code if a legitimate JPEG image contains this code in its EXIF data and the .php extension is used in the name parameter. A remote attacker can exploit this issue by using a specially crafted JPEG image with malicious EXIF data containing PHP code.Recommendations:
For versions through 9.14.0, consider disabling the save img action in the config file as a temporary workaround until a patch is available.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Responsive Filemanager