Directory Traversal Vulnerability in Tecrail Responsive FileManager Affects Multiple Versions
CVE-2018-15536

5.5MEDIUM

Key Information:

Vendor

Tecrail

Vendor
CVE Published:
24 August 2018

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2018-15536?

The vulnerability in Tecrail's Responsive FileManager is caused by improper validation of file paths within the system's extraction process. This allows attackers to craft malicious archives that, when processed, could overwrite critical files on the server. The issue particularly arises in the ajax_calls.php file, leading to potential unauthorized file access and manipulation, thereby posing significant risks to data integrity and system security.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

EPSS Score

6% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.