CVE-2020-36246
HIGHAmaze File Manager < 3.5.1 - OS Command Injection via Symbolic Link
Title source: llmDescription
Amaze File Manager before 3.5.1 allows attackers to obtain root privileges via shell metacharacters in a symbolic link.
References (2)
Core 2
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/TeamAmaze/AmazeFileManager/releases/tag/v3.5.1
Third Party Advisory x_refsource_misc
https://compass-security.com/fileadmin/Research/Advisories/2020-18_CSNC-2020-030_Amaze_FileManager_Privilege_Escalation.txt
Scores
CVSS v3
7.8
EPSS
0.0045
EPSS Percentile
36.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (1)
amaze_file_manager_project/amaze_file_manager
< 3.5.1
Published
Feb 19, 2021
Tracked Since
Feb 18, 2026