PT-2024-35167 · Unknown · File Manager
Catferq
·
Published
2024-11-13
·
Updated
2024-11-19
·
CVE-2024-52306
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FileManager versions prior to 3.0.9
Description
The issue is related to the deserialization of untrusted data from the
mimes parameter, which could lead to remote code execution. This was fixed in version 3.0.9.Recommendations
For versions prior to 3.0.9, update to version 3.0.9 to resolve the issue. As a temporary workaround, consider restricting access to the
mimes parameter to minimize the risk of exploitation. A composer update will solve the issue in a non-breaking way.Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
File Manager