High severity8.8NVD Advisory· Published Feb 2, 2023· Updated Jun 17, 2026
CVE-2022-46604
CVE-2022-46604
Description
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leading to arbitrary code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Tecrail/Responsive FileManagerdescription
- Range: <=9.9.5
<=9.9.5+ 1 more
- (no CPE)range: <=9.9.5
- cpe:2.3:a:tecrail:responsive_filemanager:*:*:*:*:*:*:*:*range: <=9.9.5
Patches
Vulnerability mechanics
References
4- github.com/trippo/ResponsiveFilemanager/blob/v9.9.5/filemanager/execute.phpnvdThird Party Advisory
- github.com/trippo/ResponsiveFilemanager/blob/v9.9.6/changelog.txtnvdRelease NotesThird Party Advisory
- packetstormsecurity.com/files/171720/Responsive-FileManager-9.9.5-Remote-Shell-Upload.htmlnvd
- medium.com/%40_sadshade/file-extention-bypass-in-responsive-filemanager-9-5-5-leading-to-rce-authenticated-3290eddc54e7nvd
News mentions
0No linked articles in our index yet.