Easy FileManager 1.1 iOS – Multiple Web Vulnerabilities
Multiple persistent input validation vulnerabilities are detected in the Easytime Studio Easy File Manager v1.1 mobile web-application. The vulnerabilities are located in the `name` and `path` value of the `upload` and `create` module. Remote attackers are able to inject own malicious script codes to the application-side of the vulnerable module. The request method to inject is POST and the attack vector is located on the application-side. The security risk of the persistent input validation vulnerabilities are estimated as high with a cvss (common vulnerability scoring system) count of 7.9. Exploitation of the persistent input validation vulnerability requires a low privilege web-application user account and low user interaction. Successful exploitation of the vulnerability results in session hijacking, persistent phishing attacks, persistent external redirects to malicious source and persistent manipulation of affected or connected module context.