S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2018-14728 Scanner

CVE-2018-14728 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in Responsive FileManager

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-14728
9.8
CVSS

upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Responsive FileManager is a popular file management solution that enables website owners to manage files on their websites quickly and easily. It is used to simplify and speed up the process of uploading and organizing files on a website. This tool is widely used by website owners and developers due to its simplicity and straightforward interface. It is particularly useful for managing visual and media files on websites.

One alarming discovery that has recently been identified and disclosed is the vulnerability code CVE-2018-14728 found in Responsive FileManager 9.13.1. This vulnerability exploits the url parameter of upload.php and can be used for Server-side Request Forgery (SSRF). This SSRF vulnerability makes it possible for an attacker to send crafted requests to the server through the web browser of a victim.

When exploited, this vulnerability can lead to a chain of attacks on the target system, such as stealing sensitive data or launching further attacks inside the targeted network. SSRF vulnerabilities provide a path for attackers to access internal resources or services that are not accessible from the internet. As a result of this vulnerability, an attacker can manipulate the network and extract data without the consent of the website owner or user.

In conclusion, security should be a top priority for all website owners and developers. Thanks to the pro features of the s4e.io platform, users can quickly and easily learn about vulnerabilities in their digital assets. It provides a comprehensive security assessment of web applications that guarantees a risk-free and secure online space. By leveraging the power of this platform, website owners and developers can safeguard their data and their users' data from threats and cyber-attacks. It is imperative to stay vigilant and prioritize security continuously, both in the digital space and in our everyday lives.

 

REFERENCES

Solution Advice

The following precautions can be taken to protect against this vulnerability:

  • Install a web application firewall to scrutinize incoming and outgoing traffic
  • Regularly update the Responsive FileManager with the latest patches and updates
  • Disable URLs in the file manager or keep the file management application behind a secure login page
  • Enforce strict input validation across the web application
  • Monitor your web application for suspicious activities and carry out regular risk assessments

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-14728 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in Responsive FileManager | S4E