Sceawere

Vulnerability Detail

CVE-2026-32577UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Frontend File Manager XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
16h ago
Vendor
N-Media
Product
Frontend File Manager
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in Frontend File Manager <= 23.6 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-06T09:17:43.297Z",
  "pubdate": "2026-10-06T09:17:43.297Z",
  "executiveSummary": "The Frontend File Manager plugin, in versions 23.6 and below, is susceptible to an unauthenticated Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability allows unauthenticated remote attackers to inject arbitrary JavaScript code into the web application's frontend, which is then executed within the security context of a user's browser session.\nThe primary impact involves the unauthorized execution of scripts that can lead to session hijacking, credential theft, redirection to malicious domains, or unauthorized actions performed on behalf of the victim.\nThe risk is categorized as high, as it does not require prior authentication or privileged access to trigger the payload.\nThe vulnerability highlights a failure in input sanitization or output encoding mechanisms within the plugin's frontend delivery architecture.\nUsers of the affected versions are at risk of client-side attacks, which can be leveraged to compromise administrative sessions if an administrator interacts with the malicious content.",
  "technicalDetails": "The vulnerability stems from improper neutralization of user-supplied input before rendering it in the browser, a classic failure of input sanitization/output encoding principles.\nIn versions 23.6 and earlier, the Frontend File Manager plugin fails to adequately sanitize data passed to the frontend interface. Because this component is accessible without authentication, an attacker can craft a specific HTTP request containing a malicious script payload.\nThe attack flow begins when an attacker crafts a URI or POST request containing obfuscated or direct JavaScript payloads targeting the vulnerable component. Once the payload reaches the server and is processed, the application reflects this input back to the user's browser without appropriate escaping or contextual encoding.\nWhen a victim, which could include a privileged administrative user, navigates to the affected page, the malicious script executes automatically. The script operates within the victim's browser session, granting the attacker access to document objects, cookies, and local storage.\nTechnically, the vulnerability exists because the plugin fails to implement consistent cross-site scripting prevention controls. Standard security headers or Content Security Policy (CSP) configurations may be bypassed if the application itself is the vector for reflected or stored script injection.\nExploitation does not require high-level privileges, as the entry point is exposed to anonymous users. The payload behavior is limited only by the attacker's capability to craft JavaScript that interacts with the DOM. Post-exploitation impact is severe, potentially allowing for the exfiltration of session tokens, CSRF token theft, or the execution of unauthorized administrative functions if the victim has such rights.\nThis vulnerability is systemic to the plugin architecture, affecting all implementations of the Frontend File Manager up to and including version 23.6."
}
CVE-2026-32577: Frontend File Manager XSS Vulnerability (HIGH Severity, CVSS: 7.1) | Sceawere