9.9
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.
Basic Information
ID
CVE-2025-46093
Source
mitre
Published
Aug 4, 2025 at 00:00
Modified
Aug 5, 2025 at 16:22
Affected Product
Vendor
LiquidFiles
Product
LiquidFiles
Affected Versions
LiquidFiles LiquidFiles 0