CVE-2025-46093
Last modified
CVE-2025-46093 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Liquidfiles | Liquidfiles | < 4.1.2 |
References
- https://gist.github.com/nikolai0x/f61a8bfcdaa244e0c46931d74d10c4eaThird Party Advisory
- https://projectblack.io/blog/liquidfiles-vulnerability-authenticated-rce/Exploit, Third Party Advisory
- https://projectblack.io/blog/liquidfiles-vulnerability-authenticated-rce/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-46093?
How severe is CVE-2025-46093?
How do I fix CVE-2025-46093?
Are you affected by CVE-2025-46093?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
