Impact
The vulnerability lies in the Alexantr Filemanager component, allowing a remote attacker to execute arbitrary code via the filemanager.php file in version 1.0, which could compromise confidentiality, integrity, and availability of the system.
Affected Systems
Alexantr Filemanager version 1.0 is affected. No other vendors, products, or versions are listed in the current data.
Risk and Exploitability
The risk is high, with a CVSS score of 9.1, due to the remote execution capability. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through HTTP requests targeting the vulnerable filemanager.php component, and exploitation requires no special access beyond reachability of the web application.
OpenCVE Enrichment