CVE-2020-36246

HIGH

Amaze File Manager < 3.5.1 - OS Command Injection via Symbolic Link

Title source: llm
STIX 2.1

Description

Amaze File Manager before 3.5.1 allows attackers to obtain root privileges via shell metacharacters in a symbolic link.

References (2)

Core 2

Scores

CVSS v3 7.8
EPSS 0.0045
EPSS Percentile 36.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
amaze_file_manager_project/amaze_file_manager < 3.5.1
Published Feb 19, 2021
Tracked Since Feb 18, 2026