{"dataType":"CVE_RECORD","cveMetadata":{"state":"PUBLISHED","cveId":"CVE-2025-46093","assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","dateUpdated":"2025-08-05T16:22:50.895Z","dateReserved":"2025-04-22T00:00:00.000Z","datePublished":"2025-08-04T00:00:00.000Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"LiquidFiles","vendor":"LiquidFiles","versions":[{"lessThan":"4.1.2","status":"affected","version":"0","versionType":"custom"}]}],"descriptions":[{"lang":"en","value":"LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-732","description":"CWE-732 Incorrect Permission Assignment for Critical Resource","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre","dateUpdated":"2025-08-04T22:25:21.372Z"},"references":[{"url":"https://docs.liquidfiles.com/release_notes/version_4-1-x.html"},{"url":"https://projectblack.io/blog/liquidfiles-vulnerability-authenticated-rce/"},{"url":"https://gist.github.com/nikolai0x/f61a8bfcdaa244e0c46931d74d10c4ea"}],"x_generator":{"engine":"enrichogram 0.0.1"},"metrics":[{"cvssV3_1":{"version":"3.1","baseScore":9.9,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:liquidfiles:liquidfiles:*:*:*:*:*:*:*:*","versionEndExcluding":"4.1.2"}]}]}]},"adp":[{"references":[{"url":"https://projectblack.io/blog/liquidfiles-vulnerability-authenticated-rce/","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-08-05T16:22:47.610432Z","id":"CVE-2025-46093","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-08-05T16:22:50.895Z"}}]},"dataVersion":"5.1"}