A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to access the full file manager functionality including reading, writing, deleting, and uploading files anywhere on the server filesystem.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-10 11:17
Updated : 2026-08-28 18:51
NVD link : CVE-2026-72593
Mitre link : CVE-2026-72593
CVE.ORG link : CVE-2026-72593
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
