PT-2025-31874 · Unknown · Liquidfiles

Nikolai0X

·

Published

2025-08-04

·

Updated

2025-08-05

·

CVE-2025-46093

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LiquidFiles versions prior to 4.1.2
Description LiquidFiles versions prior to 4.1.2 support FTP SITE CHMOD for mode 6777 (setuid and setgid). This allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.
Recommendations Update LiquidFiles to version 4.1.2 or later.

Exploit

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2025-46093

Affected Products

Liquidfiles