← Vulnerability feed

Vulnerability record · CVE-2020-10567 · published 14 March 2020

CVE-2020-10567: Tecrail responsive filemanager improper input validation vulnerability

Tecrail · Responsive Filemanager

An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent. This makes it possible to execute PHP code if a legitimate JPEG image contains this code in the EXIF data, and the .php extension is used in the name parameter. (A potential fast patch is to disable the save_img action in the config file.)

9.8 CVSS 3.1 Critical EPSS 20% · top 2.7% CWE-20 · Improper input validation
9.8CVSS 3.1 base score, v2 7.5
20%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent. This makes it possible to execute PHP code if a legitimate JPEG image contains this code in the EXIF data, and the .php extension is used in the name parameter. (A potential fast patch is to disable the save_img action in the config file.)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-10567 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-44276Tecrail responsive filemanager unrestricted file upload vulnerabilityIn Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.EPSS 2.3%9.8CVE-2017-20145Tecrail responsive filemanager path traversal vulnerabilityA vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to path traversal. The att…EPSS 1.0%9.8CVE-2020-10212Tecrail responsive filemanager server-side request forgery (ssrf) vulnerabilityupload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it…EPSS 1.5%9.8CVE-2018-14728Responsive FileManager upload.php SSRF via url parameterResponsive FileManager 9.13.1 exposes an SSRF flaw in upload.php through the url parameter, allowing the server to fetch attacker-controlled URLs. Th…EPSS 77%analysed8.8CVE-2022-46604Tecrail responsive filemanager unrestricted file upload vulnerabilityAn issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP fi…EPSS 8.6%8.6CVE-2018-18867Tecrail responsive filemanager server-side request forgery (ssrf) vulnerabilityAn SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exists because of an incompl…EPSS 1.5%7.5CVE-2018-20789Tecrail responsive filemanager path traversal vulnerabilitytecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary directory as a consequence of a paths[0] path traversal mitigati…EPSS 3.6%7.5CVE-2018-20790Tecrail responsive filemanager path traversal vulnerabilitytecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0] path traversal mitigation by…EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2020-10567), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.