Record summary

CVE-2018-14728 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBResponsive Filemanager 9.13.1 - Server-Side Request ForgeryExploitDB exploitby GUIA BRAHIM FOUADNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALResponsive filemanager 9.13.1 Server-Side Request ForgeryCVSS 9.8

Responsive filemanager 9.13.1 is susceptible to server-side request forgery in upload.php via the url parameter.

Impact

An attacker can exploit this vulnerability to bypass security controls, access internal resources, and potentially perform further attacks.

Remediation

Upgrade to a patched version of Responsive Filemanager or apply the necessary security patches to mitigate the SSRF vulnerability.

WeaknessesCWE-918
Authorsmadrobot
Template tagscve2018cvessrflfipacketstormedbintrusivetecrailvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:tecrail:responsive_filemanager:9.13.1:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3