CVE-2022-46604: Tecrail Responsive Filemanager

High severity, CVSS 8.8. EPSS: 8.6% chance of exploitation in the next 30 days.

An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leading to arbitrary code execution.

Affected products

  • Tecrail Responsive Filemanager: up to and including 9.9.5

Published 2023-02-02. Last modified 2026-06-17.