CVE-2025-46093

LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.
Configurations

Configuration 1 (hide)

cpe:2.3:a:liquidfiles:liquidfiles:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-08-04 23:15

Updated : 2025-08-07 14:29


NVD link : CVE-2025-46093

Mitre link : CVE-2025-46093

CVE.ORG link : CVE-2025-46093


JSON object : View

Products Affected

liquidfiles

  • liquidfiles
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource