Executive brief
Alexantr filemanager is a web-based tool used for managing files on a server. A security vulnerability in version 1.0 allows remote attackers to upload and execute malicious code, which could lead to a complete takeover of the web server and unauthorized access to all stored data.
Technical details
A Remote Code Execution (RCE) vulnerability exists in Alexantr filemanager v1.0. The flaw is located within the filemanager.php component, which fails to properly validate or restrict file uploads. A remote, unauthenticated attacker can exploit this by uploading a malicious script (such as a PHP shell) to the server and then accessing it directly via a web request. Successful exploitation allows for arbitrary command execution with the privileges of the web server user.
Affected products
- Alexantr filemanager 1.0
Timeline
- 2026-06-29: disclosed: Initial disclosure and CVE assignment.
- 2026-06-29: advisory: NVD publication date.