CVE-2025-46093

LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.
Configurations

Configuration 1 (hide)

cpe:2.3:a:liquidfiles:liquidfiles:*:*:*:*:*:*:*:*

History

07 Aug 2025, 14:29

Type Values Removed Values Added
First Time Liquidfiles liquidfiles
Liquidfiles
CPE cpe:2.3:a:liquidfiles:liquidfiles:*:*:*:*:*:*:*:*
References () https://docs.liquidfiles.com/release_notes/version_4-1-x.html - () https://docs.liquidfiles.com/release_notes/version_4-1-x.html - Release Notes
References () https://gist.github.com/nikolai0x/f61a8bfcdaa244e0c46931d74d10c4ea - () https://gist.github.com/nikolai0x/f61a8bfcdaa244e0c46931d74d10c4ea - Third Party Advisory
References () https://projectblack.io/blog/liquidfiles-vulnerability-authenticated-rce/ - () https://projectblack.io/blog/liquidfiles-vulnerability-authenticated-rce/ - Exploit, Third Party Advisory

05 Aug 2025, 17:15

Type Values Removed Values Added
References () https://projectblack.io/blog/liquidfiles-vulnerability-authenticated-rce/ - () https://projectblack.io/blog/liquidfiles-vulnerability-authenticated-rce/ -

05 Aug 2025, 14:34

Type Values Removed Values Added
Summary
  • (es) LiquidFiles anterior a 4.1.2 admite FTP SITE CHMOD para el modo 6777 (setuid y setgid), lo que permite a los usuarios de FTPDrop ejecutar código arbitrario como root aprovechando la función Actionscript y la configuración de sudoers.

04 Aug 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-04 23:15

Updated : 2025-08-07 14:29


NVD link : CVE-2025-46093

Mitre link : CVE-2025-46093

CVE.ORG link : CVE-2025-46093


JSON object : View

Products Affected

liquidfiles

  • liquidfiles
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource