Back

MEDIUM

Cross-Site Scripting in PHP File Manager by Dulldusk

Published Jun 6, 2024

Description

Vulnerability in Dulldusk's PHP File Manager affecting version 1.7.8. This vulnerability consists of an XSS through the fm_current_dir parameter of index.php. An attacker could send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session.

Affected products

Remediation

Vendor solution

There is no reported solution at this time.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Jun 6, 2024
Updated Aug 1, 2024
Reserved Jun 6, 2024
CISA Vulnrichment
Updated Jun 6, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a