PT-2024-35167 · Unknown · File Manager

Catferq

·

Published

2024-11-13

·

Updated

2024-11-19

·

CVE-2024-52306

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FileManager versions prior to 3.0.9
Description The issue is related to the deserialization of untrusted data from the mimes parameter, which could lead to remote code execution. This was fixed in version 3.0.9.
Recommendations For versions prior to 3.0.9, update to version 3.0.9 to resolve the issue. As a temporary workaround, consider restricting access to the mimes parameter to minimize the risk of exploitation. A composer update will solve the issue in a non-breaking way.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-52306
GHSA-8237-957H-H2C2

Affected Products

File Manager