Impact
An unrestricted upload vulnerability in the dialog.php file of Trippo ResponsiveFilemanager allows a remote attacker to upload arbitrary files. If exploited, this flaw can enable the attacker to place executable code on the server, potentially leading to remote code execution or server compromise.
Affected Systems
Trippo ResponsiveFilemanager versions 9.14.0 and earlier are affected by the vulnerability in dialog.php. No specific function name is disclosed, but the flaw resides in an unknown function within that file.
Risk and Exploitability
The vulnerability receives a CVSS score of 6.9, indicating moderate severity. No EPSS score is available, so the exploitation probability is unknown, but the public release of an exploit suggests that attacks are feasible. The vulnerability is remote, and the lack of a KEV entry means it is not listed among current known exploited vulnerabilities. A remote attacker with access to the dialog.php endpoint can trigger the upload, giving the attack a low barrier to execution.
OpenCVE Enrichment