Directory Traversal Vulnerability in Tecrail Responsive FileManager
CVE-2018-15535
7.5HIGH
Key Information:
- Vendor
Tecrail
- Status
- Vendor
- CVE Published:
- 24 August 2018
Badges
๐พ Exploit Exists๐ฃ EPSS 79%
What is CVE-2018-15535?
The Tecrail Responsive FileManager prior to version 9.13.4 is susceptible to a directory traversal vulnerability. This flaw allows an attacker to exploit external inputs in the /filemanager/ajax_calls.php file to construct pathnames that can escape the intended restricted directory. By using sequences such as '..', an attacker may navigate to unauthorized locations on the server, potentially gaining access to sensitive files and data.
References
EPSS Score
79% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
