Directory Traversal Vulnerability in Tecrail Responsive FileManager
CVE-2018-15535

7.5HIGH

Key Information:

Vendor

Tecrail

Vendor
CVE Published:
24 August 2018

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸฃ EPSS 79%

What is CVE-2018-15535?

The Tecrail Responsive FileManager prior to version 9.13.4 is susceptible to a directory traversal vulnerability. This flaw allows an attacker to exploit external inputs in the /filemanager/ajax_calls.php file to construct pathnames that can escape the intended restricted directory. By using sequences such as '..', an attacker may navigate to unauthorized locations on the server, potentially gaining access to sensitive files and data.

References

EPSS Score

79% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.