Security vulnerability affecting Phoca Commander (v4.0.0 & v5.0.1)
Posted: 29 Jul 2025, 11:08
Hello,
I have identified a security vulnerability affecting Phoca Commander (v4.0.0 & v5.0.1) and have sent a detailed report to info@phoca.cz as well as through the contact form on your website.
I’m posting here just to ensure the message was received, as I understand this is a sensitive issue and I want to make sure it doesn't go unnoticed. The report includes technical details and reproduction steps for a remote code execution (RCE) scenario caused by improper file validation.
Please let me know if you’ve received the report or if there’s a preferred way to communicate securely.
Best regards,
SJ
I have identified a security vulnerability affecting Phoca Commander (v4.0.0 & v5.0.1) and have sent a detailed report to info@phoca.cz as well as through the contact form on your website.
I’m posting here just to ensure the message was received, as I understand this is a sensitive issue and I want to make sure it doesn't go unnoticed. The report includes technical details and reproduction steps for a remote code execution (RCE) scenario caused by improper file validation.
Please let me know if you’ve received the report or if there’s a preferred way to communicate securely.
Best regards,
SJ