PT-2026-24149 · Unknown+1 · File Manager+1

Rusi-Sec

·

Published

2026-03-09

·

Updated

2026-03-13

·

CVE-2026-30919

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions facileManager versions prior to 6.0.4
Description facileManager is a suite of web applications designed for system administrators. A stored cross-site scripting (XSS) issue exists in the fmDNS module. This type of attack occurs when an application receives data from an untrusted source and includes it in HTTP responses without proper sanitization. Stored XSS, also known as persistent or second-order XSS, allows malicious scripts to be stored on the target server and executed by other users.
Recommendations Update to version 6.0.4 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-30919
GHSA-2339-H9QW-Q6VF

Affected Products

File Manager
Fmdns