PT-2025-6408 · Teamamaze · Amaze File Manager
Blackbeard666
·
Published
2025-02-11
·
Updated
2025-02-12
·
CVE-2024-33469
CVSS v3.1
7.9
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Team Amaze Amaze File Manager versions 3.8.5 through 3.10
Description
An issue in Team Amaze Amaze File Manager allows a local attacker to execute arbitrary code via the
onCreate method of DatabaseViewerActivity.java.Recommendations
For versions 3.8.5 through 3.9, update to version 3.10 to resolve the issue.
As a temporary workaround, consider disabling the
onCreate method of DatabaseViewerActivity.java until a patch is available.Exploit
Fix
Code Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Amaze File Manager