LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://docs.liquidfiles.com/release_notes/version_4-1-x.html | release notes |
https://projectblack.io/blog/liquidfiles-vulnerability-authenticated-rce/ | third party advisory exploit |
https://gist.github.com/nikolai0x/f61a8bfcdaa244e0c46931d74d10c4ea | third party advisory |