Directory Traversal Vulnerability in Tecrail Responsive FileManager Affects Multiple Versions
CVE-2018-15536
Key Information:
- Vendor
Tecrail
- Status
- Vendor
- CVE Published:
- 24 August 2018
Badges
What is CVE-2018-15536?
The vulnerability in Tecrail's Responsive FileManager is caused by improper validation of file paths within the system's extraction process. This allows attackers to craft malicious archives that, when processed, could overwrite critical files on the server. The issue particularly arises in the ajax_calls.php file, leading to potential unauthorized file access and manipulation, thereby posing significant risks to data integrity and system security.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
