9.9
CVE-2025-46093
- EPSS 0.5%
- Veröffentlicht 04.08.2025 00:00:00
- Zuletzt bearbeitet 07.08.2025 14:29:07
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Liquidfiles ≫ Liquidfiles Version < 4.1.2
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.5% | 0.387 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| cve@mitre.org | 9.9 | 3.1 | 6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
https://docs.liquidfiles.com/release_notes/version_4-1-x.html
https://projectblack.io/blog/liquidfiles-vulnerability-authenticated-rce/
https://gist.github.com/nikolai0x/f61a8bfcdaa244e0c46931d74d10c4ea