Vulnerability Description
An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exists because of an incomplete fix for CVE-2018-15495.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tecrail | Responsive Filemanager | 9.13.4 |
Related Weaknesses (CWE)
References
- https://github.com/trippo/ResponsiveFilemanager/issues/506ExploitThird Party Advisory
- https://github.com/trippo/ResponsiveFilemanager/issues/506ExploitThird Party Advisory
FAQ
What is CVE-2018-18867?
CVE-2018-18867 is a vulnerability with a CVSS score of 8.6 (HIGH). An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exists because of an incomplete fix for CVE-2018-15495.
How severe is CVE-2018-18867?
CVE-2018-18867 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-18867?
Check the references section above for vendor advisories and patch information. Affected products include: Tecrail Responsive Filemanager.