Impact
A missing authentication check in dulldusk/phpfm versions up to 1.8.0 enables an unauthenticated remote attacker to perform any file manager operation—reading, writing, deleting, and uploading files—across the entire server filesystem. This flaw falls under CWE-306 and results in complete loss of confidentiality, integrity, and availability for the affected system.
Affected Systems
Vendors: dulldusk; Product: phpfm. Affected versions include all releases up to and including 1.8.0.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV. Exploitation requires only HTTP access to the web interface; an attacker needs no valid credentials, making this a straightforward remote unauthenticated threat.
OpenCVE Enrichment