Description
Vulnerability in Dulldusk's PHP File Manager affecting version 1.7.8. This vulnerability consists of an XSS through the fm_current_dir parameter of index.php. An attacker could send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session.
No analysis available yet.
Remediation
Vendor Solution
There is no reported solution at this time.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46846 | Vulnerability in Dulldusk's PHP File Manager affecting version 1.7.8. This vulnerability consists of an XSS through the fm_current_dir parameter of index.php. An attacker could send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session. |
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T21:18:06.988Z
Reserved: 2024-06-06T07:34:47.669Z
Link: CVE-2024-5673
Updated: 2024-08-01T21:18:06.988Z
Status : Modified
Published: 2024-06-06T11:15:49.807
Modified: 2024-11-21T09:48:08.057
Link: CVE-2024-5673
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD