Impact
An issue in Responsive File Manager version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component. The vulnerability permits the attacker to run commands on the underlying server, potentially compromising confidentiality, integrity, and availability. The official description does not specify a root cause, but it is inferred that the download handler may be vulnerable to malicious input processing.
Affected Systems
The affected system is Responsive File Manager version 9.14.0, a web‑based file management application. No specific vendors are listed in the CNA data, but the product itself is identified as the point of impact.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, yet the nature of remote code execution implies a high exploitation risk. The likely attack vector is web‑based, inferred from the vulnerable force_download.php endpoint. Without mitigation, an attacker could run arbitrary commands, access sensitive data, or launch further attacks on the host.
OpenCVE Enrichment