// For flags

CVE-2020-10212

 

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it is possible for a DNS hostname to resolve to an internal IP address. For example, an SSRF attempt may succeed if a .ico filename is added to the PATH_INFO. Also, an attacker could create a DNS hostname that resolves to the 0.0.0.0 IP address for DNS pinning. NOTE: this issue exists because of an incomplete fix for CVE-2018-14728.

El archivo upload.php en Responsive FileManager versiones 9.13.4 y 9.14.0, permite un ataque de tipo SSRF por medio del parámetro url porque el bloqueo de la extensión de archivo se maneja inapropiadamente y porque es posible que un nombre de host DNS se resuelva en una dirección IP interna. Por ejemplo, un intento de SSRF puede tener éxito si un nombre de archivo .ico es agregado al PATH_INFO. Además, un atacante podría crear un nombre de host DNS que se resuelva en la dirección IP 0.0.0.0 para una DNS pinning. NOTA: este problema se presenta debido a una corrección incompleta para CVE-2018-14728.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-03-06 CVE Reserved
  • 2020-03-06 CVE Published
  • 2024-02-11 EPSS Updated
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Tecrail
Search vendor "Tecrail"
Responsive Filemanager
Search vendor "Tecrail" for product "Responsive Filemanager"
9.13.4
Search vendor "Tecrail" for product "Responsive Filemanager" and version "9.13.4"
-
Affected
Tecrail
Search vendor "Tecrail"
Responsive Filemanager
Search vendor "Tecrail" for product "Responsive Filemanager"
9.14.0
Search vendor "Tecrail" for product "Responsive Filemanager" and version "9.14.0"
-
Affected