PT-2024-10575 · Unknown · Frontend File Manager+1

Ethicalhack3R

·

Published

2024-10-16

·

Updated

2024-10-30

·

CVE-2016-15042

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Frontend File Manager versions prior to 4.0 N-Media Post Front-end Form versions prior to 1.1
Description The issue allows unauthenticated attackers to upload arbitrary files on the server due to missing file type validation via the nm filemanager upload file and nm postfront upload file AJAX actions, potentially making remote code execution possible.
Recommendations For Frontend File Manager versions prior to 4.0, update to version 4.0 or later to resolve the issue. For N-Media Post Front-end Form versions prior to 1.1, update to version 1.1 or later to resolve the issue. As a temporary workaround, consider disabling the nm filemanager upload file and nm postfront upload file AJAX actions until a patch is available.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2016-15042

Affected Products

Frontend File Manager
N-Media Post Front-End Form