HIGH🇵🇱 Wersja polska

CVE-2021-43397

CVSS 8.8v3.1pub. 2021-11-11upd. 2024-11-21

LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Liquidfiles

    APP
    Liquidfiles
    < 3.6.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-46093CRITICAL9.9PL ✓same product

RCE jako root w LiquidFiles — FTP SITE CHMOD z setuid/setgid

CVE-2020-29071CRITICAL9.0PL ✓same product

XSS w LiquidFiles — eskalacja uprawnień do root przez funkcję Shares

CVE-2025-56132HIGH7.3same product

LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality....

CVE-2023-4393MEDIUM5.4same product

HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker ...

CVE-2021-30140MEDIUM5.4same product

LiquidFiles 3.4.15 has stored XSS through the "send email" functionality when sending a file via email to an a...