PT-2023-14963 · Tecrail · Tecrail Responsive Filemanager
Published
2023-02-02
·
Updated
2024-09-10
·
CVE-2022-46604
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tecrail Responsive FileManager versions 9.9.5 and below
Description
An issue in Tecrail Responsive FileManager allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leading to arbitrary code execution. This has been observed to be used by threat actors.
Recommendations
For versions 9.9.5 and below, consider disabling the file upload feature until a patch is available to prevent arbitrary code execution. Restrict access to the file extension check mechanism to minimize the risk of exploitation. Avoid using the file upload feature in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tecrail Responsive Filemanager