CVE-2025-46093 Information
Aug 05, 2025
cve
Description
LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid) which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.
Reference
https://docs.liquidfiles.com/release_notes/version_4-1-x.html https://gist.github.com/nikolai0x/f61a8bfcdaa244e0c46931d74d10c4ea https://projectblack.io/blog/liquidfiles-vulnerability-authenticated-rce/
Related CNNVD
CNNVD-202508-272 (Published: 2025-08-04)
Share on: