Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-53894 1 Dulldusk 1 Phpfm 2025-12-17 9.8 Critical
phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP files to the server.
CVE-2024-5673 1 Dulldusk 1 Phpfilemanager 2024-11-21 6.1 Medium
Vulnerability in Dulldusk's PHP File Manager affecting version 1.7.8. This vulnerability consists of an XSS through the fm_current_dir parameter of index.php. An attacker could send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session.