9.8
CVSSv3

CVE-2020-10567

Published: 14/03/2020 Updated: 07/03/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Responsive Filemanager up to and including 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent. This makes it possible to execute PHP code if a legitimate JPEG image contains this code in the EXIF data, and the .php extension is used in the name parameter. (A potential fast patch is to disable the save_img action in the config file.)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tecrail responsive filemanager

Exploits

ZwiiCMS version 12204 suffers from an authenticated remote code execution vulnerability ...