CVE-2022-40797

CRITICALCVSS 9.8/10EPSS 2.56%

Last modified

CVE-2022-40797 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.). EPSS estimates a 2.56% chance of exploitation in the next 30 days.

Description

Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
2.56%

83.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
RoxyfilemanRoxy Fileman1.4.6

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-40797?
Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)
How severe is CVE-2022-40797?
CVE-2022-40797 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 2.56% probability of exploitation in the next 30 days.
How do I fix CVE-2022-40797?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-40797?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST