CVE-2022-40797 - How a Simple Upload Bypass in Roxy Fileman 1.4.6 Leads to Remote Code Execution (.phar Upload Exploit)
If you use Roxy Fileman 1.4.6—an open-source web file manager popular among PHP developers for WYSIWYG editors like TinyMCE and CKEditor—there’