PoC Index

CVE-2025-46093

CRITICAL 9.9EPSS 0.5%

LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.9 CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS
0.53% chance of exploitation in the next 30 days, 43th percentile
Published
2025-08-04
Updated
2025-08-05

Proof-of-concept exploits (1)

References

Related