CVE-2018-15495: Tecrail Responsive Filemanager
High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.
/filemanager/upload.php in Responsive FileManager before 9.13.3 allows Directory Traversal and SSRF because the url parameter is used directly in a curl_exec call, as demonstrated by a file:///etc/passwd value.
Affected products
- Tecrail Responsive Filemanager: before 9.13.3 (fixed in 9.13.3)
Published 2018-08-18. Last modified 2026-06-17.