Vulnerability in Dulldusk's PHP File Manager affecting version 1.7.8. This vulnerability consists of an XSS through the fm_current_dir parameter of index.php. An attacker could send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session.
Fixes

Solution

There is no reported solution at this time.


Workaround

No workaround given by the vendor.

History

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00121}

epss

{'score': 0.00175}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-01T21:18:06.988Z

Reserved: 2024-06-06T07:34:47.669Z

Link: CVE-2024-5673

cve-icon Vulnrichment

Updated: 2024-08-01T21:18:06.988Z

cve-icon NVD

Status : Modified

Published: 2024-06-06T11:15:49.807

Modified: 2024-11-21T09:48:08.057

Link: CVE-2024-5673

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.